7.3

CVE-2025-28025

Exploit
TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in downloadFile.cgi through the v14 parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Totolink ≫ A830r Firmware Version 4.1.2cu.5182_b20201102
   Totolink ≫ A830r Version -
Totolink ≫ A950rg Firmware Version 4.1.2cu.5161_b20200903
   Totolink ≫ A950rg Version -
Totolink ≫ A3000ru Firmware Version 5.9c.5185_b20201128
   Totolink ≫ A3000ru Version -
Totolink ≫ A3100r Firmware Version 4.1.2cu.5247_b20211129
   Totolink ≫ A3100r Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.303
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.3 3.9 3.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

https://locrian-lightning-dc7.notion.site/BufferOverflow1-19e8e5e2b1a280bfbe52ec9975287f77
Third Party Advisory
Exploit
https://locrian-lightning-dc7.notion.site/BufferOverflow1-19e8e5e2b1a280bfbe52ec9975287f77?pvs=73
Third Party Advisory
Exploit