TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth remote command execution vulnerability in the NTPSyncWithHost function through the hostTime parameter.
Metrics
Affected Vendors & Products
References
History
Tue, 29 Apr 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Totolink
Totolink a3000ru Totolink a3000ru Firmware Totolink a3100r Totolink a3100r Firmware Totolink a800r Totolink a800r Firmware Totolink a810r Totolink a810r Firmware Totolink a830r Totolink a830r Firmware Totolink a950rg Totolink a950rg Firmware |
|
CPEs | cpe:2.3:h:totolink:a3000ru:-:*:*:*:*:*:*:* cpe:2.3:h:totolink:a3100r:-:*:*:*:*:*:*:* cpe:2.3:h:totolink:a800r:-:*:*:*:*:*:*:* cpe:2.3:h:totolink:a810r:-:*:*:*:*:*:*:* cpe:2.3:h:totolink:a830r:-:*:*:*:*:*:*:* cpe:2.3:h:totolink:a950rg:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:a3000ru_firmware:5.9c.5185_b20201128:*:*:*:*:*:*:* cpe:2.3:o:totolink:a3100r_firmware:4.1.2cu.5247_b20211129:*:*:*:*:*:*:* cpe:2.3:o:totolink:a800r_firmware:4.1.2cu.5137_b20200730:*:*:*:*:*:*:* cpe:2.3:o:totolink:a810r_firmware:4.1.2cu.5182_b20201026:*:*:*:*:*:*:* cpe:2.3:o:totolink:a830r_firmware:4.1.2cu.5182_b20201102:*:*:*:*:*:*:* cpe:2.3:o:totolink:a950rg_firmware:4.1.2cu.5161_b20200903:*:*:*:*:*:*:* |
|
Vendors & Products |
Totolink
Totolink a3000ru Totolink a3000ru Firmware Totolink a3100r Totolink a3100r Firmware Totolink a800r Totolink a800r Firmware Totolink a810r Totolink a810r Firmware Totolink a830r Totolink a830r Firmware Totolink a950rg Totolink a950rg Firmware |
Wed, 23 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV3_1
|
Tue, 22 Apr 2025 14:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a pre-auth remote command execution vulnerability in the NTPSyncWithHost function through the hostTime parameter. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-04-22T00:00:00.000Z
Updated: 2025-04-23T15:01:19.895Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-28034

Updated: 2025-04-23T15:01:14.382Z

Status : Analyzed
Published: 2025-04-22T14:15:25.263
Modified: 2025-04-29T16:18:58.493
Link: CVE-2025-28034

No data.