CVE-2025-28035

TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:totolink:a830r_firmware:4.1.2cu.5182_b20201102:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a830r:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:totolink:a3100r_firmware:4.1.2cu.5247_b20211129:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a3100r:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:totolink:a810r_firmware:4.1.2cu.5182_b20201026:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a810r:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:totolink:a800r_firmware:4.1.2cu.5137_b20200730:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a800r:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:totolink:a3000ru_firmware:5.9c.5185_b20201128:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a3000ru:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:totolink:a950rg_firmware:4.1.2cu.5161_b20200903:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a950rg:-:*:*:*:*:*:*:*

History

29 Apr 2025, 16:14

Type Values Removed Values Added
First Time Totolink
Totolink a830r Firmware
Totolink a800r Firmware
Totolink a3100r
Totolink a3000ru Firmware
Totolink a3000ru
Totolink a3100r Firmware
Totolink a810r
Totolink a950rg Firmware
Totolink a950rg
Totolink a830r
Totolink a800r
Totolink a810r Firmware
CPE cpe:2.3:o:totolink:a3000ru_firmware:5.9c.5185_b20201128:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a3100r:-:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a950rg:-:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a830r:-:*:*:*:*:*:*:*
cpe:2.3:o:totolink:a950rg_firmware:4.1.2cu.5161_b20200903:*:*:*:*:*:*:*
cpe:2.3:o:totolink:a830r_firmware:4.1.2cu.5182_b20201102:*:*:*:*:*:*:*
cpe:2.3:o:totolink:a800r_firmware:4.1.2cu.5137_b20200730:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a810r:-:*:*:*:*:*:*:*
cpe:2.3:o:totolink:a810r_firmware:4.1.2cu.5182_b20201026:*:*:*:*:*:*:*
cpe:2.3:o:totolink:a3100r_firmware:4.1.2cu.5247_b20211129:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a3000ru:-:*:*:*:*:*:*:*
cpe:2.3:h:totolink:a800r:-:*:*:*:*:*:*:*
References () https://locrian-lightning-dc7.notion.site/RCE1-1a98e5e2b1a28081880dd817104b3af4?pvs=73 - () https://locrian-lightning-dc7.notion.site/RCE1-1a98e5e2b1a28081880dd817104b3af4?pvs=73 - Exploit, Third Party Advisory
References () https://locrian-lightning-dc7.notion.site/CVE-2025-28035-CVE-2025-28036-RCE1-1a98e5e2b1a28081880dd817104b3af4 - () https://locrian-lightning-dc7.notion.site/CVE-2025-28035-CVE-2025-28036-RCE1-1a98e5e2b1a28081880dd817104b3af4 - Exploit, Third Party Advisory

23 Apr 2025, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-78
References
  • () https://locrian-lightning-dc7.notion.site/CVE-2025-28035-CVE-2025-28036-RCE1-1a98e5e2b1a28081880dd817104b3af4 -

23 Apr 2025, 14:08

Type Values Removed Values Added
Summary
  • (es) Se descubrió que TOTOLINK A830R V4.1.2cu.5182_B20201102 contenía una vulnerabilidad de ejecución de comando remoto previo a la autorización en la función setNoticeCfg a través del parámetro NoticeUrl.

22 Apr 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-22 18:15

Updated : 2025-04-29 16:14


NVD link : CVE-2025-28035

Mitre link : CVE-2025-28035

CVE.ORG link : CVE-2025-28035


JSON object : View

Products Affected

totolink

  • a830r_firmware
  • a950rg_firmware
  • a3000ru_firmware
  • a800r
  • a3000ru
  • a830r
  • a800r_firmware
  • a810r_firmware
  • a810r
  • a950rg
  • a3100r
  • a3100r_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')