Buffer Overflow Vulnerability in TOTOLINK A800R Router by TOTOLINK
CVE-2025-28018

7.3HIGH

Key Information:

Vendor
TOTOLINK
Vendor
CVE Published:
23 April 2025

Summary

The TOTOLINK A800R router is susceptible to a buffer overflow vulnerability via the downloadFile.cgi component, which can be exploited through crafted inputs using the v14 parameter. This flaw potentially allows an attacker to execute arbitrary code remotely, compromising the integrity and security of the device and the network it’s connected to.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.