ID

VAR-202504-3251


CVE

CVE-2025-28030


TITLE

TOTOLINK  of  A810R  Stack-based buffer overflow vulnerability in firmware

Trust: 0.8

sources: JVNDB: JVNDB-2025-004100

DESCRIPTION

TOTOLINK A810R V4.1.2cu.5182_B20201026 was discovered to contain a stack overflow via the startTime and endTime parameters in setParentalRules function. TOTOLINK of A810R A stack-based buffer overflow vulnerability exists in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. TOTOLINK A810R is a wireless dual-band router from China's TOTOLINK Electronics. TOTOLINK A810R V4.1.2cu.5182_B20201026 has a buffer overflow vulnerability. The vulnerability is caused by the startTime and endTime parameters in the setParentalRules function failing to correctly verify the length of the input data. Remote attackers can exploit this vulnerability to execute arbitrary code on the system or cause a denial of service

Trust: 2.16

sources: NVD: CVE-2025-28030 // JVNDB: JVNDB-2025-004100 // CNVD: CNVD-2025-09864

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-09864

AFFECTED PRODUCTS

vendor:totolinkmodel:a810rscope:eqversion:4.1.2cu.5182_b20201026

Trust: 1.0

vendor:totolinkmodel:a810rscope:eqversion: -

Trust: 0.8

vendor:totolinkmodel:a810rscope: - version: -

Trust: 0.8

vendor:totolinkmodel:a810rscope:eqversion:a810r firmware 4.1.2cu.5182 b20201026

Trust: 0.8

vendor:totolinkmodel:a810r v4.1.2cu.5182 b20201026scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2025-09864 // JVNDB: JVNDB-2025-004100 // NVD: CVE-2025-28030

CVSS

SEVERITY

CVSSV2

CVSSV3

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2025-28030
value: HIGH

Trust: 1.0

OTHER: JVNDB-2025-004100
value: HIGH

Trust: 0.8

CNVD: CNVD-2025-09864
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-09864
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2025-28030
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 5.9
version: 3.1

Trust: 1.0

OTHER: JVNDB-2025-004100
baseSeverity: HIGH
baseScore: 8.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2025-09864 // JVNDB: JVNDB-2025-004100 // NVD: CVE-2025-28030

PROBLEMTYPE DATA

problemtype:CWE-121

Trust: 1.0

problemtype:Stack-based buffer overflow (CWE-121) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2025-004100 // NVD: CVE-2025-28030

EXTERNAL IDS

db:NVDid:CVE-2025-28030

Trust: 3.2

db:JVNDBid:JVNDB-2025-004100

Trust: 0.8

db:CNVDid:CNVD-2025-09864

Trust: 0.6

sources: CNVD: CNVD-2025-09864 // JVNDB: JVNDB-2025-004100 // NVD: CVE-2025-28030

REFERENCES

url:https://locrian-lightning-dc7.notion.site/bufferoverflow6-19f8e5e2b1a2803db1d9ce7b4d06e2e0?pvs=73

Trust: 2.4

url:https://nvd.nist.gov/vuln/detail/cve-2025-28030

Trust: 0.8

sources: CNVD: CNVD-2025-09864 // JVNDB: JVNDB-2025-004100 // NVD: CVE-2025-28030

SOURCES

db:CNVDid:CNVD-2025-09864
db:JVNDBid:JVNDB-2025-004100
db:NVDid:CVE-2025-28030

LAST UPDATE DATE

2025-05-17T03:57:18.349000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-09864date:2025-05-15T00:00:00
db:JVNDBid:JVNDB-2025-004100date:2025-04-30T05:07:00
db:NVDid:CVE-2025-28030date:2025-04-29T16:21:07.407

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-09864date:2025-05-13T00:00:00
db:JVNDBid:JVNDB-2025-004100date:2025-04-30T00:00:00
db:NVDid:CVE-2025-28030date:2025-04-22T16:15:45.123