CVE-2025-6486: TOTOLINK A3002R formWlanMultipleAP stack-based overflow
A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been declared as critical. This vulnerability affects the function formWlanMultipleAP of the file /boafrm/formWlanMultipleAP. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6486?
CVE-2025-6486 is classified as a critical vulnerability.
How do I fix CVE-2025-6486?
To fix CVE-2025-6486, update your TOTOLINK A3002R device to the latest firmware version provided by the vendor.
What type of vulnerability is CVE-2025-6486?
CVE-2025-6486 is a stack-based buffer overflow vulnerability affecting the function formWlanMultipleAP.
Which devices are affected by CVE-2025-6486?
CVE-2025-6486 affects the TOTOLINK A3002R device running version 1.1.1-B20200824.0128.
What is the attack vector for CVE-2025-6486?
The attack vector for CVE-2025-6486 involves manipulating the argument submit-url in the formWlanMultipleAP function.