5.4

CVE-2025-45867

Exploit
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the static_dns1 parameter in the formIpv6Setup interface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Totolink ≫ A3002r Firmware Version 4.0.0-b20230531.1404
   Totolink ≫ A3002r Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.86% 0.913
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 5.4 2.8 2.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-121 Stack-based Buffer Overflow

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/258/ids/36.html
Product
https://github.com/Jiangxiazhe/IOT_hack/blob/main/TOTOLINK/A3002R/10/overflow.md
Third Party Advisory
Exploit