cbcvebase.
CVE-2025-28017
published 2025-04-23

CVE-2025-28017: TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter.

medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter.

Affected

1 ranges
VendorProductVersion rangeFixed in
totolinka800r_firmware