PT-2025-9129 · Totolink · Totolink A3002Ru

Published

2025-02-28

·

Updated

2025-03-02

·

CVE-2025-25609

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOlink A3002R version V1.1.1-B20200824.0128
Description The issue arises from a buffer overflow due to improper input validation of the static ipv6 parameter in the formIpv6Setup interface of the /bin/boa API endpoint.
Recommendations For version V1.1.1-B20200824.0128, as a temporary workaround, consider restricting access to the formIpv6Setup interface in the /bin/boa API endpoint until a patch is available. Avoid using the static ipv6 parameter in the affected API endpoint until the issue is resolved.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-25609

Affected Products

Totolink A3002Ru