TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 contain a pre-auth buffer overflow vulnerability in the setNoticeCfg function through the IpForm parameter.
References
Link | Resource |
---|---|
https://locrian-lightning-dc7.notion.site/BufferOverflow6-19f8e5e2b1a28052bda1f6ede9db341d | Third Party Advisory Exploit |
https://locrian-lightning-dc7.notion.site/BufferOverflow6-19f8e5e2b1a28052bda1f6ede9db341d | Third Party Advisory Exploit |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
History
29 Apr 2025, 16:19
Type | Values Removed | Values Added |
---|---|---|
First Time |
Totolink
Totolink a830r Firmware Totolink a800r Firmware Totolink a3100r Totolink a3000ru Firmware Totolink a3000ru Totolink a3100r Firmware Totolink a810r Totolink a950rg Firmware Totolink a950rg Totolink a830r Totolink a800r Totolink a810r Firmware |
|
CPE | cpe:2.3:o:totolink:a3000ru_firmware:5.9c.5185_b20201128:*:*:*:*:*:*:* cpe:2.3:h:totolink:a950rg:-:*:*:*:*:*:*:* cpe:2.3:h:totolink:a3100r:-:*:*:*:*:*:*:* cpe:2.3:h:totolink:a830r:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:a950rg_firmware:4.1.2cu.5161_b20200903:*:*:*:*:*:*:* cpe:2.3:o:totolink:a830r_firmware:4.1.2cu.5182_b20201102:*:*:*:*:*:*:* cpe:2.3:o:totolink:a800r_firmware:4.1.2cu.5137_b20200730:*:*:*:*:*:*:* cpe:2.3:h:totolink:a810r:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:a810r_firmware:4.1.2cu.5182_b20201026:*:*:*:*:*:*:* cpe:2.3:o:totolink:a3100r_firmware:4.1.2cu.5247_b20211129:*:*:*:*:*:*:* cpe:2.3:h:totolink:a3000ru:-:*:*:*:*:*:*:* cpe:2.3:h:totolink:a800r:-:*:*:*:*:*:*:* |
|
References | () https://locrian-lightning-dc7.notion.site/BufferOverflow6-19f8e5e2b1a28052bda1f6ede9db341d - Third Party Advisory, Exploit |
23 Apr 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-121 | |
References | () https://locrian-lightning-dc7.notion.site/BufferOverflow6-19f8e5e2b1a28052bda1f6ede9db341d - | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.3 |
23 Apr 2025, 14:08
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
22 Apr 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-22 14:15
Updated : 2025-04-29 16:19
NVD link : CVE-2025-28032
Mitre link : CVE-2025-28032
CVE.ORG link : CVE-2025-28032
JSON object : View
Products Affected
totolink
- a830r_firmware
- a950rg_firmware
- a3000ru_firmware
- a800r
- a3000ru
- a830r
- a800r_firmware
- a810r_firmware
- a810r
- a950rg
- a3100r
- a3100r_firmware
CWE
CWE-121
Stack-based Buffer Overflow