{"advisories":[{"id":"EUVD-2025-10972","source":"euvd","title":"The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.","url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-10972"}],"cve":"CVE-2025-28137","epss":{"score":0.34089},"mitre":{"cpes":[],"created":"2025-04-15T00:00:00+00:00","description":"The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{}},"mitre_repo_path":"cves/2025/28xxx/CVE-2025-28137.json","references":["https://github.com/Zerone0x00/CVE/blob/main/TOTOLINK/CVE-2025-28137.md","https://sudsy-eyeliner-a59.notion.site/RCE1-1ab72b8cd95f80d09eded269810f3756?pvs=4"],"title":null,"updated":"2025-04-15T17:35:32.265000+00:00","vendors":[],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:h:totolink:a810r:-:*:*:*:*:*:*:*","cpe:2.3:o:totolink:a810r_firmware:4.1.2cu.5182_b20201026:*:*:*:*:*:*:*"],"created":"2025-04-15T14:15:41.400000+00:00","description":"The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2025/CVE-2025-28137.json","references":["https://github.com/Zerone0x00/CVE/blob/main/TOTOLINK/CVE-2025-28137.md","https://sudsy-eyeliner-a59.notion.site/RCE1-1ab72b8cd95f80d09eded269810f3756","https://sudsy-eyeliner-a59.notion.site/RCE1-1ab72b8cd95f80d09eded269810f3756?pvs=4"],"title":null,"updated":"2026-06-17T09:04:35.993000+00:00","vendors":["totolink","totolink$PRODUCT$a810r","totolink$PRODUCT$a810r_firmware"],"weaknesses":["CWE-78"]},"opencve":{"changes":[{"created":"2025-04-15T14:15:00+00:00","data":[{"details":{"new":"The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.","old":null},"type":"description"},{"details":{"added":["https://github.com/Zerone0x00/CVE/blob/main/TOTOLINK/CVE-2025-28137.md","https://sudsy-eyeliner-a59.notion.site/RCE1-1ab72b8cd95f80d09eded269810f3756?pvs=4"],"removed":[]},"type":"references"}],"id":"979e2dae-ce5d-473e-85b7-5b0cfa6d7db3"},{"created":"2025-04-15T18:15:00+00:00","data":[{"details":{"added":["CWE-78"],"removed":[]},"type":"weaknesses"},{"details":{"added":["https://sudsy-eyeliner-a59.notion.site/RCE1-1ab72b8cd95f80d09eded269810f3756"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"88e5f73b-c2ad-4096-ab6d-1349dd99bc7a"},{"created":"2025-04-29T16:45:00+00:00","data":[{"details":["totolink","totolink$PRODUCT$a810r","totolink$PRODUCT$a810r_firmware"],"type":"first_time"},{"details":{"added":["cpe:2.3:h:totolink:a810r:-:*:*:*:*:*:*:*","cpe:2.3:o:totolink:a810r_firmware:4.1.2cu.5182_b20201026:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["totolink","totolink$PRODUCT$a810r","totolink$PRODUCT$a810r_firmware"],"removed":[]},"type":"vendors"}],"id":"f655ba38-c5e7-49d8-890b-675f6b6b56a8"}],"cpes":{"data":["cpe:2.3:h:totolink:a810r:-:*:*:*:*:*:*:*","cpe:2.3:o:totolink:a810r_firmware:4.1.2cu.5182_b20201026:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2025-04-15T00:00:00+00:00","provider":"mitre"},"description":{"data":"The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"vulnrichment"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.34089},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/Zerone0x00/CVE/blob/main/TOTOLINK/CVE-2025-28137.md","https://sudsy-eyeliner-a59.notion.site/RCE1-1ab72b8cd95f80d09eded269810f3756","https://sudsy-eyeliner-a59.notion.site/RCE1-1ab72b8cd95f80d09eded269810f3756?pvs=4"],"providers":["mitre","nvd","vulnrichment"]},"title":{"data":null,"provider":null},"updated":{"data":"2025-04-29T16:23:23.197000+00:00","provider":"nvd"},"vendors":{"data":["totolink","totolink$PRODUCT$a810r","totolink$PRODUCT$a810r_firmware"],"providers":["nvd"]},"weaknesses":{"data":["CWE-78"],"providers":["nvd","vulnrichment"]}},"vulnrichment":{"cpes":[],"created":"2025-04-15T00:00:00+00:00","description":"The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"references":["https://sudsy-eyeliner-a59.notion.site/RCE1-1ab72b8cd95f80d09eded269810f3756"],"title":null,"updated":"2025-04-15T17:35:26.641000+00:00","vendors":[],"vulnrichment_repo_path":"2025/28xxx/CVE-2025-28137.json","weaknesses":["CWE-78"]}}