📦 A800r Firmware

by Totolink

🔍 What is A800r Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-28034

CRITICAL CVSS 9.8 Apr 22, 2025

This CVE describes a pre-authentication remote command execution vulnerability in multiple TOTOLINK router models. Attackers can execute arbitrary commands on affected devices without authentication b...

CVE-2025-28138

CRITICAL CVSS 9.8 Mar 27, 2025

This vulnerability allows unauthenticated attackers to execute arbitrary commands on TOTOLINK A800R routers by exploiting improper input validation in the setNoticeCfg function. Attackers can gain ful...

CVE-2022-26206

CRITICAL CVSS 9.8 Mar 15, 2022

This CVE describes a critical command injection vulnerability in multiple Totolink router models. Attackers can execute arbitrary system commands by sending specially crafted requests to the setLangua...

CVE-2022-26208

CRITICAL CVSS 9.8 Mar 15, 2022

This CVE describes a command injection vulnerability in multiple Totolink router models that allows attackers to execute arbitrary commands via the webWlanIdx parameter in the setWebWlanIdx function. ...

CVE-2022-26210

CRITICAL CVSS 9.8 Mar 15, 2022

This CVE describes a command injection vulnerability in multiple Totolink router models that allows attackers to execute arbitrary commands via the FileName parameter in the setUpgradeFW function. Att...

CVE-2022-26212

CRITICAL CVSS 9.8 Mar 15, 2022

This CVE describes a command injection vulnerability in multiple Totolink router models that allows attackers to execute arbitrary commands via the setDeviceName function. Attackers can exploit this b...

CVE-2022-26214

CRITICAL CVSS 9.8 Mar 15, 2022

This CVE describes a command injection vulnerability in multiple Totolink router models that allows attackers to execute arbitrary commands via the host_time parameter in the NTPSyncWithHost function....

CVE-2022-25076

CRITICAL CVSS 9.8 Feb 24, 2022

This CVE describes a command injection vulnerability in TOTOLink A800R routers that allows attackers to execute arbitrary commands via the QUERY_STRING parameter. Attackers can gain complete control o...

CVE-2025-4496

HIGH CVSS 8.8 May 10, 2025

A critical buffer overflow vulnerability in TOTOLINK routers allows remote attackers to execute arbitrary code by manipulating the FileName parameter in the CloudACMunualUpdate function. This affects ...

CVE-2025-28020

HIGH CVSS 7.3 Apr 23, 2025

This CVE describes a buffer overflow vulnerability in TOTOLINK A800R routers through the downloadFile.cgi endpoint's v25 parameter. Attackers can exploit this to execute arbitrary code or crash the de...

CVE-2025-28018

HIGH CVSS 7.3 Apr 23, 2025

This CVE describes a buffer overflow vulnerability in TOTOLINK A800R routers through the downloadFile.cgi endpoint's v14 parameter. Attackers can exploit this to execute arbitrary code or crash the de...

CVE-2025-28032

HIGH CVSS 7.3 Apr 22, 2025

This CVE describes a pre-authentication buffer overflow vulnerability in multiple TOTOLINK router models. Attackers can exploit this by sending specially crafted requests to the setNoticeCfg function ...

CVE-2022-28935

HIGH CVSS 7.2 Jul 6, 2022

This CVE describes a command injection vulnerability in multiple Totolink router models that allows attackers to execute arbitrary commands on affected devices. The vulnerability affects specific firm...