CVE-2025-28036

TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
Configurations

No configuration.

History

23 Apr 2025, 15:16

Type Values Removed Values Added
References
  • () https://locrian-lightning-dc7.notion.site/CVE-2025-28035-CVE-2025-28036-RCE1-1a98e5e2b1a28081880dd817104b3af4 -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-78

23 Apr 2025, 14:08

Type Values Removed Values Added
Summary
  • (es) Se descubrió que TOTOLINK A950RG V4.1.2cu.5161_B20200903 contenía una vulnerabilidad de ejecución de comando remoto previo a la autorización en la función setNoticeCfg a través del parámetro NoticeUrl.

22 Apr 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-22 18:15

Updated : 2025-04-23 15:16


NVD link : CVE-2025-28036

Mitre link : CVE-2025-28036

CVE.ORG link : CVE-2025-28036


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')