PT-2025-20905 · Totolink · Totolink A3002Ru

Jiangxiazhe

·

Published

2025-05-13

·

Updated

2025-06-16

·

CVE-2025-45859

CVSS v3.1

5.4

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TOTOLINK A3002R version 4.0.0-B20230531.1404
Description The issue is related to a buffer overflow in the formMapDelDevice interface of the TOTOLINK A3002R router's firmware. This occurs due to the lack of size checking for input data, which can be exploited by a remote attacker to impact the confidentiality and integrity of protected information. The buffer overflow is specifically caused by the bandstr parameter in the formMapDelDevice interface.
Recommendations For TOTOLINK A3002R version 4.0.0-B20230531.1404, as a temporary workaround, consider disabling the formMapDelDevice interface until a patch is available. Restrict access to the bandstr parameter in the formMapDelDevice interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-05835
CVE-2025-45859

Affected Products

Totolink A3002Ru