Shodan
Maps
Images
Monitor
Developer
More...
Dashboard
View Api Docs
Vulnerabilities
By Date
Known Exploited
Advanced Search
Vulnerable Software
Vendors
Products
Vulnerability Details CVE-2025-28017
TOTOLINK A800R V4.1.2cu.5032_B20200408 is vulnerable to Command Injection in downloadFile.cgi via the QUERY_STRING parameter.
Exploit prediction scoring system (EPSS) score
EPSS Score
0.144
EPSS Ranking
94.1%
CVSS Severity
CVSS v3 Score
6.5
References
https://locrian-lightning-dc7.notion.site/CVE-2025-28017-TOTOLINK-A800R-RCE-1938e5e2b1a280d696bbd25699fb5e97
https://locrian-lightning-dc7.notion.site/TOTOLINK-A800R-RCE-1938e5e2b1a280d696bbd25699fb5e97
Products affected by CVE-2025-28017
Totolink
»
A800r
»
Version:
N/A
cpe:2.3:h:totolink:a800r:-
Totolink
»
A800r Firmware
»
Version:
4.1.2cu.5032_b20200408
cpe:2.3:o:totolink:a800r_firmware:4.1.2cu.5032_b20200408
Products
Monitor
Search Engine
Developer API
Maps
Bulk Data
Images
Snippets
Pricing
Membership
API Subscriptions
Enterprise
Contact Us
support@shodan.io
Shodan ® - All rights reserved