CVE-2025-25610

HIGH

Totolink A3002r Firmware - Buffer Overflow

Title source: rule
STIX 2.1

Description

TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the static_gw parameter in the formIpv6Setup interface of /bin/boa.

Scores

CVSS v3 8.0
EPSS 0.0006
EPSS Percentile 19.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-120
Status published
Products (1)
totolink/a3002r_firmware 1.1.1-b20200824.0128
Published Feb 28, 2025
Tracked Since Feb 18, 2026