CVE-2025-45859: Buffer Overflow
Published May 13, 2025
·Updated
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the bandstr parameter in the formMapDelDevice interface.
Affected Software
3 affected components
TOTOLINK A3002R
All of the following
TOTOLINK A3002R Firmware=4.0.0-b20230531.1404
TOTOLINK A3002R
Event History
May 13, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-45859?
CVE-2025-45859 has a high severity rating due to the potential for remote code execution caused by the buffer overflow.
2
How do I fix CVE-2025-45859?
To fix CVE-2025-45859, update the TOTOLINK A3002R firmware to the latest version provided by the manufacturer.
3
What specific vulnerability does CVE-2025-45859 exploit?
CVE-2025-45859 exploits a buffer overflow vulnerability via the bandstr parameter in the formMapDelDevice interface.
4
What is affected by CVE-2025-45859?
CVE-2025-45859 affects the TOTOLINK A3002R router running firmware version v4.0.0-B20230531.1404.
5
Can CVE-2025-45859 lead to unauthorized access?
Yes, CVE-2025-45859 can lead to unauthorized access and remote code execution, compromising the device's security.