TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://locrian-lightning-dc7.notion.site/CVE-2025-28035-CVE-2025-28036-RCE1-1a98e5e2b1a28081880dd817104b3af4 | Exploit Third Party Advisory |
https://locrian-lightning-dc7.notion.site/RCE1-1a98e5e2b1a28081880dd817104b3af4?pvs=73 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
History
29 Apr 2025, 16:14
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:totolink:a3000ru:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:a3100r_firmware:4.1.2cu.5247_b20211129:*:*:*:*:*:*:* cpe:2.3:h:totolink:a810r:-:*:*:*:*:*:*:* cpe:2.3:h:totolink:a830r:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:a950rg_firmware:4.1.2cu.5161_b20200903:*:*:*:*:*:*:* cpe:2.3:h:totolink:a3100r:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:a830r_firmware:4.1.2cu.5182_b20201102:*:*:*:*:*:*:* cpe:2.3:o:totolink:a3000ru_firmware:5.9c.5185_b20201128:*:*:*:*:*:*:* cpe:2.3:h:totolink:a800r:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:a800r_firmware:4.1.2cu.5137_b20200730:*:*:*:*:*:*:* cpe:2.3:o:totolink:a810r_firmware:4.1.2cu.5182_b20201026:*:*:*:*:*:*:* cpe:2.3:h:totolink:a950rg:-:*:*:*:*:*:*:* |
|
First Time |
Totolink a950rg Firmware
Totolink a830r Totolink a3100r Firmware Totolink a3000ru Firmware Totolink a950rg Totolink a810r Totolink a800r Firmware Totolink a800r Totolink a3000ru Totolink a810r Firmware Totolink a3100r Totolink a830r Firmware Totolink |
|
References | () https://locrian-lightning-dc7.notion.site/CVE-2025-28035-CVE-2025-28036-RCE1-1a98e5e2b1a28081880dd817104b3af4 - Exploit, Third Party Advisory | |
References | () https://locrian-lightning-dc7.notion.site/RCE1-1a98e5e2b1a28081880dd817104b3af4?pvs=73 - Exploit, Third Party Advisory |
23 Apr 2025, 15:16
Type | Values Removed | Values Added |
---|---|---|
References |
|
22 Apr 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-22 18:15
Updated : 2025-04-29 16:14
NVD link : CVE-2025-28035
Mitre link : CVE-2025-28035
JSON object : View
Products Affected
totolink
- a810r_firmware
- a3000ru
- a3100r_firmware
- a800r_firmware
- a800r
- a3000ru_firmware
- a830r_firmware
- a950rg_firmware
- a830r
- a950rg
- a3100r
- a810r
CWE
No CWE.