PT-2025-9131 · Totolink · Totolink A3002Ru

Sunnyyangyaya

·

Published

2025-02-28

·

Updated

2025-09-02

·

CVE-2025-25635

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOlink A3002R version V1.1.1-B20200824.0128
Description The issue arises from a buffer overflow due to improper input validation of the pppoe dns1 parameter in the formIpv6Setup interface of the /bin/boa endpoint.
Recommendations For TOTOlink A3002R version V1.1.1-B20200824.0128, as a temporary workaround, consider restricting access to the formIpv6Setup interface in the /bin/boa endpoint to minimize the risk of exploitation. Avoid using the pppoe dns1 parameter in the affected interface until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-12690
CVE-2025-25635

Affected Products

Totolink A3002Ru