CVE-2025-45864: Buffer Overflow
Published May 13, 2025
·Updated
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolStart parameter in the formDhcpv6s interface.
Affected Software
3 affected components
TOTOLINK A3002R
All of the following
TOTOLINK A3002R Firmware=4.0.0-b20230531.1404
TOTOLINK A3002R
Event History
May 13, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-45864?
CVE-2025-45864 is rated as a high severity vulnerability due to its potential for remote exploitation.
2
How do I fix CVE-2025-45864?
To mitigate CVE-2025-45864, users should update their TOTOLINK A3002R firmware to the latest version provided by the manufacturer.
3
What type of vulnerability is CVE-2025-45864?
CVE-2025-45864 is classified as a buffer overflow vulnerability affecting the DHCPv6 service.
4
What systems are affected by CVE-2025-45864?
CVE-2025-45864 specifically affects the TOTOLINK A3002R model running firmware version v4.0.0-B20230531.1404.
5
Can CVE-2025-45864 be exploited remotely?
Yes, CVE-2025-45864 can be exploited remotely if the vulnerable service is accessible.