Buffer Overflow Vulnerability in TOTOLINK Router A3002R
CVE-2025-45867

5.4MEDIUM

Key Information:

Vendor

TOTOLINK

Status
Vendor
CVE Published:
13 May 2025

What is CVE-2025-45867?

The TOTOLINK A3002R router (version 4.0.0-B20230531.1404) has been identified with a serious security flaw, allowing for buffer overflow through the 'static_dns1' parameter within the formIpv6Setup interface. This vulnerability could potentially be exploited to execute arbitrary code, leading to unauthorized access or control over the device. Network administrators should take immediate action to mitigate risks associated with this vulnerability by applying necessary patches or updates as advised by the vendor.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.