CVE-2025-28032

TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 contain a pre-auth buffer overflow vulnerability in the setNoticeCfg function through the IpForm parameter.
Configurations

No configuration.

History

23 Apr 2025, 15:15

Type Values Removed Values Added
CWE CWE-121
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3
References () https://locrian-lightning-dc7.notion.site/BufferOverflow6-19f8e5e2b1a28052bda1f6ede9db341d - () https://locrian-lightning-dc7.notion.site/BufferOverflow6-19f8e5e2b1a28052bda1f6ede9db341d -

23 Apr 2025, 14:08

Type Values Removed Values Added
Summary
  • (es) TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128 y A3100R V4.1.2cu.5247_B20211129 contienen una vulnerabilidad de desbordamiento de búfer previo a la autorización en la función setNoticeCfg a través del parámetro IpForm.

22 Apr 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-22 14:15

Updated : 2025-04-23 15:15


NVD link : CVE-2025-28032

Mitre link : CVE-2025-28032

CVE.ORG link : CVE-2025-28032


JSON object : View

Products Affected

No product.

CWE
CWE-121

Stack-based Buffer Overflow