CVE-2025-28017 | TOTOLINK A800R 4.1.2cu.5032_B20200408 downloadFile.cgi QUERY_STRING command injection
A vulnerability was found in TOTOLINK A800R 4.1.2cu.5032_B20200408. It has been declared as critical. This vulnerability affects unknown code of the file downloadFile.cgi. The manipulation of the argument QUERY_STRING leads to command injection.
This vulnerability was named CVE-2025-28017. The attack can be initiated remotely. There is no exploit available.