CVE-2025-28019
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Apr 23, 2025
Updated: May 6, 2025
CWE ID 120
Summary
CVE-2025-28019 is a newly identified buffer overflow vulnerability affecting the TOTOLINK A800R V4.1.2cu.5137_B20200730 firmware. This issue resides in the downloadFile.cgi component, which could allow an attacker to send maliciously crafted data, causing the buffer to overflow. Successful exploitation of this vulnerability could result in arbitrary code execution, potentially leading to unauthorized access or system compromise. Users are advised to update their firmware as soon as a patch is available to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- TOTOLINK