Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12096 | TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter. |
Tue, 06 May 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Totolink
Totolink a800r Totolink a800r Firmware |
|
| CPEs | cpe:2.3:h:totolink:a800r:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:a800r_firmware:4.1.2cu.5032_b20200408:*:*:*:*:*:*:* |
|
| Vendors & Products |
Totolink
Totolink a800r Totolink a800r Firmware |
Thu, 24 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 | |
| Metrics |
cvssV3_1
|
Wed, 23 Apr 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-24T15:54:33.085Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-28017
Updated: 2025-04-24T15:54:29.609Z
Status : Analyzed
Published: 2025-04-23T17:16:52.690
Modified: 2025-05-06T20:35:52.033
Link: CVE-2025-28017
No data.
OpenCVE Enrichment
No data.
EUVD