CVE-2025-28138

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 27, 2025
Updated: Apr 15, 2025
CWE ID 78

Summary

CVE-2025-28138 is a pre-authentication remote command execution vulnerability affecting the TOTOLINK A800R V4.1.2cu.5137_B20200730 firmware. This issue is located in the setNoticeCfg function, which can be exploited through a maliciously crafted NoticeUrl parameter. Successful exploitation grants an attacker the ability to execute arbitrary commands on the targeted device, posing a significant risk to network security. It is recommended that users update their firmware to a patched version to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share