TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
References
Link | Resource |
---|---|
https://locrian-lightning-dc7.notion.site/RCE1-1a98e5e2b1a28081880dd817104b3af4 | Exploit Third Party Advisory |
https://locrian-lightning-dc7.notion.site/CVE-2025-28035-CVE-2025-28036-RCE1-1a98e5e2b1a28081880dd817104b3af4 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
History
29 Apr 2025, 16:13
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:totolink:a950rg:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:a830r_firmware:4.1.2cu.5182_b20201102:*:*:*:*:*:*:* cpe:2.3:h:totolink:a830r:-:*:*:*:*:*:*:* cpe:2.3:h:totolink:a3100r:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:a950rg_firmware:4.1.2cu.5161_b20200903:*:*:*:*:*:*:* cpe:2.3:o:totolink:a810r_firmware:4.1.2cu.5182_b20201026:*:*:*:*:*:*:* cpe:2.3:h:totolink:a800r:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:a3000ru_firmware:5.9c.5185_b20201128:*:*:*:*:*:*:* cpe:2.3:o:totolink:a800r_firmware:4.1.2cu.5137_b20200730:*:*:*:*:*:*:* cpe:2.3:h:totolink:a810r:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:a3100r_firmware:4.1.2cu.5247_b20211129:*:*:*:*:*:*:* cpe:2.3:h:totolink:a3000ru:-:*:*:*:*:*:*:* |
|
First Time |
Totolink a800r Firmware
Totolink a3100r Totolink a3000ru Totolink Totolink a830r Totolink a810r Firmware Totolink a3000ru Firmware Totolink a800r Totolink a950rg Firmware Totolink a810r Totolink a950rg Totolink a830r Firmware Totolink a3100r Firmware |
|
References | () https://locrian-lightning-dc7.notion.site/RCE1-1a98e5e2b1a28081880dd817104b3af4 - Exploit, Third Party Advisory | |
References | () https://locrian-lightning-dc7.notion.site/CVE-2025-28035-CVE-2025-28036-RCE1-1a98e5e2b1a28081880dd817104b3af4 - Exploit, Third Party Advisory |
23 Apr 2025, 15:16
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CWE | CWE-78 |
23 Apr 2025, 14:08
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
22 Apr 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-22 18:15
Updated : 2025-04-29 16:13
NVD link : CVE-2025-28036
Mitre link : CVE-2025-28036
CVE.ORG link : CVE-2025-28036
JSON object : View
Products Affected
totolink
- a810r_firmware
- a3000ru
- a3100r_firmware
- a950rg
- a810r
- a800r_firmware
- a830r
- a3100r
- a800r
- a830r_firmware
- a950rg_firmware
- a3000ru_firmware
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')