VYPR
Critical severity9.8NVD Advisory· Published Apr 22, 2025· Updated Jun 17, 2026

CVE-2025-28038

CVE-2025-28038

Description

TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the setWebWlanIdx function through the webWlanIdx parameter.

Affected products

3
  • cpe:2.3:o:totolink:ex1200t_firmware:4.1.2cu.5232_b20210713:*:*:*:*:*:*:*
  • Totolink/EX1200Tcpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: V4.1.2cu.5232_B20210713

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.