CVE-2025-45866: Buffer Overflow
Published May 13, 2025
·Updated
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the addrPoolEnd parameter in the formDhcpv6s interface.
Affected Software
3 affected components
TOTOLINK A3002R
All of the following
TOTOLINK A3002R Firmware=4.0.0-b20230531.1404
TOTOLINK A3002R
Event History
May 13, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-45866?
CVE-2025-45866 has been classified as a high-severity vulnerability due to the risk of remote code execution via buffer overflow.
2
How do I fix CVE-2025-45866?
To remediate CVE-2025-45866, you should update the TOTOLINK A3002R firmware to the latest version provided by the vendor.
3
What systems are affected by CVE-2025-45866?
CVE-2025-45866 specifically affects the TOTOLINK A3002R with firmware version v4.0.0-B20230531.1404.
4
What does CVE-2025-45866 exploit?
CVE-2025-45866 exploits a buffer overflow vulnerability in the addrPoolEnd parameter of the formDhcpv6s interface.
5
Can CVE-2025-45866 be exploited remotely?
Yes, CVE-2025-45866 can be exploited remotely, allowing attackers to potentially execute arbitrary code on the device.