The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
Publication date: Tue, 15 Apr 2025 00:00:00 +0000
Cyber News related to CVE-2025-28137
CVE-2025-28137 - The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter. ...
10 months ago
CVE-2020-28137 - Cross site request forgery (CSRF) in Genexis Platinum 4410 V2-1.28, allows attackers to cause a denial of service by continuously restarting the router. ...
4 years ago PLATINUM
CVE-2022-28137 - A missing permission check in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials. ...
2 years ago
CVE-2024-28137 - A local attacker with low privileges can perform a privilege escalation with an init script due to a TOCTOU vulnerability. ...
1 year ago Tenable.com