TOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 were found to contain a buffer overflow vulnerability in downloadFile.cgi through the v5 parameter.
CVE ID: CVE-2025-28028
CVSS Base Severity: HIGH
CVSS Base Score: 7.3
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vendor: n/a
Product: n/a
EPSS Score: 0.11% (probability of being exploited)
EPSS Percentile: 30.44% (scored less or equal to compared to others)
EPSS Date: 2025-05-22 (when was this score calculated)