CVE-2025-28021

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Apr 23, 2025
Updated: May 6, 2025
CWE ID 120

Summary

CVE-2025-28021 is a buffer overflow vulnerability affecting the TOTOLINK A810R V4.1.2cu.5182_B20201026 firmware. The issue is located in the downloadFile.cgi script and can be exploited by sending maliciously crafted input to the v14 and v3 parameters. Successful exploitation may lead to arbitrary code execution, potentially compromising the affected device and allowing unauthorized access or data theft. Users are advised to apply the latest patches and update their devices to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share