CVE-2025-6485: TOTOLINK A3002R formWlSiteSurvey os command injection
A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been classified as critical. This affects the function formWlSiteSurvey of the file /boafrm/formWlSiteSurvey. The manipulation of the argument wlanif leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6485?
CVE-2025-6485 has been classified as a critical vulnerability.
What type of vulnerability is associated with CVE-2025-6485?
CVE-2025-6485 involves OS command injection due to manipulation of the wlanif argument.
What systems are affected by CVE-2025-6485?
CVE-2025-6485 affects the TOTOLINK A3002R with firmware version 1.1.1-B20200824.0128.
How can CVE-2025-6485 be mitigated?
To mitigate CVE-2025-6485, it is recommended to update the TOTOLINK A3002R firmware to the latest version.
Is CVE-2025-6485 exploitable remotely?
Yes, CVE-2025-6485 is potentially exploitable remotely, allowing attackers to execute arbitrary commands.