VYPR
Medium severity6.5NVD Advisory· Published Apr 23, 2025· Updated Jun 17, 2026

CVE-2025-28017

CVE-2025-28017

Description

TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter.

Affected products

3
  • cpe:2.3:o:totolink:a800r_firmware:4.1.2cu.5032_b20200408:*:*:*:*:*:*:*
  • Totolink/A8000RUcpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: V4.1.2cu.5032_B20200408

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.