CVE-2025-25635: Buffer Overflow
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the pppoedns1 parameter in the formIpv6Setup interface of /bin/boa.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25635?
CVE-2025-25635 is classified as a high severity vulnerability due to the potential for buffer overflow exploitation.
How do I fix CVE-2025-25635?
To fix CVE-2025-25635, you should update the TOTOlink A3002R firmware to the latest version that addresses this buffer overflow vulnerability.
What is the impact of the CVE-2025-25635 vulnerability?
The impact of CVE-2025-25635 could lead to remote code execution or denial of service if exploited by an attacker.
Which devices are affected by CVE-2025-25635?
CVE-2025-25635 affects the TOTOlink A3002R router with the firmware version V1.1.1-B20200824.0128.
How can attackers exploit CVE-2025-25635?
Attackers can exploit CVE-2025-25635 by sending crafted requests with specially formatted pppoe_dns1 parameters to the vulnerable interface.