CVE-2025-28034

TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth remote command execution vulnerability in the NTPSyncWithHost function through the hostTime parameter.
Configurations

No configuration.

History

23 Apr 2025, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References
  • () https://locrian-lightning-dc7.notion.site/CVE-2025-28034-RCE2-1a98e5e2b1a280bebf53d868f1b1a711 -
CWE CWE-78

23 Apr 2025, 14:08

Type Values Removed Values Added
Summary
  • (es) Se descubrió que TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128 y A3100R V4.1.2cu.5247_B20211129 contenían una vulnerabilidad de ejecución remota de comandos previa a la autorización en la función NTPSyncWithHost a través del parámetro hostTime.

22 Apr 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-22 14:15

Updated : 2025-04-23 15:16


NVD link : CVE-2025-28034

Mitre link : CVE-2025-28034

CVE.ORG link : CVE-2025-28034


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')