ZeroHour

CVE-2025-28137

PoC ×3niche

Pre-auth Command Injection RCE in TOTOLINK A810R Router Firmware

CVSS 3.1
9.8 critical
EPSS
34%p98
Published
()
Modified
AI analysis

TOTOLINK A810R firmware version V4.1.2cu.5182_B20201026 contains an unauthenticated OS command injection vulnerability (CWE-78) in the setNoticeCfg function of the router's web management interface. An attacker with network access to the management interface can send a crafted request with malicious content in the NoticeUrl parameter, causing arbitrary commands to be executed on the device without any credentials or user interaction. Successful exploitation grants full command execution on the router, which an attacker can use for device takeover, traffic interception, or as a foothold for lateral movement or botnet enlistment. Only users running the TOTOLINK A810R with the affected firmware are impacted; the data does not indicate which other firmware versions or models may be affected. Public proof-of-concept exploits have been published (3 references), and the flaw carries a high EPSS score of 36.1% (98th percentile), indicating elevated near-term exploitation likelihood, though it is not yet listed in CISA's KEV and there is no confirmed in-the-wild exploitation in the provided data.

What to do: Check TOTOLINK's support site for an A810R firmware release newer than V4.1.2cu.5182_B20201026 and upgrade, since no fixed version is specified in the available data. Until patched, do not expose the router's web management interface to the WAN: disable remote administration, and restrict access to trusted clients or via firewall rules. Given the 36.1% EPSS score and published PoCs, prioritize checking logs for unexpected requests targeting setNoticeCfg/NoticeUrl on any internet-facing units.

Affected
TOTOLINK A810R firmwareV4.1.2cu.5182_B20201026
Estimated exposure
nichelikely hundreds to low thousands of internet-exposed A810R routers (single model; TOTOLINK devices collectively appear in the thousands in public internet… — The finding is limited to one specific consumer router model, and while public scan data routinely shows thousands of TOTOLINK management interfaces exposed online, a single model represents only a fraction of that population.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.

Vendors
totolink
Products
a810r firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news