CVE-2025-28137
PoC ×3nichePre-auth Command Injection RCE in TOTOLINK A810R Router Firmware
TOTOLINK A810R firmware version V4.1.2cu.5182_B20201026 contains an unauthenticated OS command injection vulnerability (CWE-78) in the setNoticeCfg function of the router's web management interface. An attacker with network access to the management interface can send a crafted request with malicious content in the NoticeUrl parameter, causing arbitrary commands to be executed on the device without any credentials or user interaction. Successful exploitation grants full command execution on the router, which an attacker can use for device takeover, traffic interception, or as a foothold for lateral movement or botnet enlistment. Only users running the TOTOLINK A810R with the affected firmware are impacted; the data does not indicate which other firmware versions or models may be affected. Public proof-of-concept exploits have been published (3 references), and the flaw carries a high EPSS score of 36.1% (98th percentile), indicating elevated near-term exploitation likelihood, though it is not yet listed in CISA's KEV and there is no confirmed in-the-wild exploitation in the provided data.
What to do: Check TOTOLINK's support site for an A810R firmware release newer than V4.1.2cu.5182_B20201026 and upgrade, since no fixed version is specified in the available data. Until patched, do not expose the router's web management interface to the WAN: disable remote administration, and restrict access to trusted clients or via firewall rules. Given the 36.1% EPSS score and published PoCs, prioritize checking logs for unexpected requests targeting setNoticeCfg/NoticeUrl on any internet-facing units.
| TOTOLINK A810R firmware | V4.1.2cu.5182_B20201026 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.
- Vendors
- totolink
- Products
- a810r firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H