CVE-2025-6487: TOTOLINK A3002R formRoute stack-based overflow
A vulnerability was found in TOTOLINK A3002R 1.1.1-B20200824.0128. It has been rated as critical. This issue affects the function formRoute of the file /boafrm/formRoute. The manipulation of the argument subnet leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6487?
CVE-2025-6487 has been rated as critical due to the potential for remote exploitation.
How do I fix CVE-2025-6487?
To fix CVE-2025-6487, update the TOTOLINK A3002R router firmware to the latest version provided by the manufacturer.
What is the impact of CVE-2025-6487?
The impact of CVE-2025-6487 includes a stack-based buffer overflow that can be exploited by remote attackers.
Which devices are affected by CVE-2025-6487?
CVE-2025-6487 affects the TOTOLINK A3002R model running version 1.1.1-B20200824.0128.
Can CVE-2025-6487 be exploited remotely?
Yes, CVE-2025-6487 can be exploited remotely through the vulnerable formRoute functionality.