TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
References
| Link | Resource |
|---|---|
| https://locrian-lightning-dc7.notion.site/RCE1-1a98e5e2b1a28081880dd817104b3af4 | Exploit Third Party Advisory |
| https://locrian-lightning-dc7.notion.site/CVE-2025-28035-CVE-2025-28036-RCE1-1a98e5e2b1a28081880dd817104b3af4 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
History
No history.
Information
Published : 2025-04-22 18:15
Updated : 2025-04-29 16:13
NVD link : CVE-2025-28036
Mitre link : CVE-2025-28036
CVE.ORG link : CVE-2025-28036
JSON object : View
Products Affected
totolink
- a3000ru
- a950rg_firmware
- a3000ru_firmware
- a800r
- a3100r
- a810r_firmware
- a950rg
- a830r_firmware
- a830r
- a3100r_firmware
- a800r_firmware
- a810r
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
