CVE-2025-28017: Totolink a800r Firmware

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter.

Affected products

  • Totolink a800r Firmware: version 4.1.2cu.5032_b20200408 only

Published 2025-04-23. Last modified 2026-06-17.