CVE-2025-28256
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Mar 28, 2025
Updated: Apr 14, 2025
CWE ID 78
Summary
CVE-2025-28256 is a newly disclosed vulnerability affecting the TOTOLINK A3100R V4.1.2cu.5247_B20211129 firmware. This issue permits a remote attacker to execute arbitrary code by exploiting a vulnerability in the /lib/cste_modules/wireless.so file's setWebWlanIdx function. By sending maliciously crafted packets to the affected device, an attacker can potentially gain unauthorized control, leading to significant security risks. It is strongly recommended that users update their firmware to patch this vulnerability as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- TOTOLINK