CVE-2025-28038
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 22, 2025
Updated: Apr 29, 2025
CWE ID 78
Summary
CVE-2025-28038 is a newly discovered vulnerability affecting the TOTOLINK EX1200T V4.1.2cu.5232_B20210713 firmware. This issue allows an unauthenticated attacker to execute remote commands on the device by exploiting a pre-authorization flaw in the setWebWlanIdx function. The vulnerability can be triggered through the webWlanIdx parameter. Successful exploitation could lead to significant compromise of the affected network device. Users are strongly advised to update their firmware as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- TOTOLINK