CVE-2025-28024

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 22, 2025
Updated: Apr 29, 2025
CWE ID 120

Summary

CVE-2025-28024 is a newly discovered vulnerability affecting the TOTOLINK A810R V4.1.2cu.5182_B20201026 firmware. This issue involves a buffer overflow in the cstecgi.cgi component, which can potentially be exploited by malicious actors to execute arbitrary code on the targeted device. Successful exploitation could lead to unauthorized access, data theft, or system crashes. Users are advised to update their firmware to the latest version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share