VYPR
Critical severity9.8NVD Advisory· Published Apr 15, 2025· Updated Jun 17, 2026

CVE-2025-28137

CVE-2025-28137

Description

The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:o:totolink:a810r_firmware:4.1.2cu.5182_b20201026:*:*:*:*:*:*:*
  • Totolink/A810Rcpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: V4.1.2cu.5182_B20201026

Patches

Vulnerability mechanics

References

3

News mentions

1