TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth remote command execution vulnerability in the NTPSyncWithHost function through the hostTime parameter.
References
Link | Resource |
---|---|
https://locrian-lightning-dc7.notion.site/RCE2-1a98e5e2b1a280bebf53d868f1b1a711?pvs=74 | Exploit Third Party Advisory |
https://locrian-lightning-dc7.notion.site/CVE-2025-28034-RCE2-1a98e5e2b1a280bebf53d868f1b1a711 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
History
29 Apr 2025, 16:18
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:totolink:a3000ru_firmware:5.9c.5185_b20201128:*:*:*:*:*:*:* cpe:2.3:h:totolink:a810r:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:a800r_firmware:4.1.2cu.5137_b20200730:*:*:*:*:*:*:* cpe:2.3:h:totolink:a950rg:-:*:*:*:*:*:*:* cpe:2.3:h:totolink:a3000ru:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:a810r_firmware:4.1.2cu.5182_b20201026:*:*:*:*:*:*:* cpe:2.3:o:totolink:a830r_firmware:4.1.2cu.5182_b20201102:*:*:*:*:*:*:* cpe:2.3:o:totolink:a3100r_firmware:4.1.2cu.5247_b20211129:*:*:*:*:*:*:* cpe:2.3:h:totolink:a800r:-:*:*:*:*:*:*:* cpe:2.3:h:totolink:a3100r:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:a950rg_firmware:4.1.2cu.5161_b20200903:*:*:*:*:*:*:* cpe:2.3:h:totolink:a830r:-:*:*:*:*:*:*:* |
|
References | () https://locrian-lightning-dc7.notion.site/RCE2-1a98e5e2b1a280bebf53d868f1b1a711?pvs=74 - Exploit, Third Party Advisory | |
References | () https://locrian-lightning-dc7.notion.site/CVE-2025-28034-RCE2-1a98e5e2b1a280bebf53d868f1b1a711 - Exploit, Third Party Advisory | |
First Time |
Totolink a950rg
Totolink a3000ru Totolink Totolink a3100r Firmware Totolink a810r Firmware Totolink a800r Firmware Totolink a830r Firmware Totolink a3000ru Firmware Totolink a800r Totolink a950rg Firmware Totolink a810r Totolink a3100r Totolink a830r |
23 Apr 2025, 15:16
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CWE | CWE-78 |
23 Apr 2025, 14:08
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
22 Apr 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-22 14:15
Updated : 2025-04-29 16:18
NVD link : CVE-2025-28034
Mitre link : CVE-2025-28034
CVE.ORG link : CVE-2025-28034
JSON object : View
Products Affected
totolink
- a830r
- a3100r_firmware
- a800r_firmware
- a810r
- a950rg_firmware
- a3000ru
- a810r_firmware
- a830r_firmware
- a3100r
- a950rg
- a3000ru_firmware
- a800r
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')