PT-2025-20416 · Totolink · Totolink A3100R

Sunnyyangyaya

·

Published

2025-05-08

·

Updated

2025-05-08

·

CVE-2025-45787

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TOTOLINK A3100R version 5.9c.1527
Description The issue is related to a Buffer Overflow that can be triggered through the comment parameter in the setIpPortFilterRules function. This allows for potential exploitation.
Recommendations For TOTOLINK A3100R version 5.9c.1527, consider restricting access to the setIpPortFilterRules function until a patch is available, and avoid using the comment parameter in this function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-10004
CVE-2025-45787

Affected Products

Totolink A3100R