CVE-2025-6939: TOTOLINK A3002RU HTTP POST Request formWlSiteSurvey buffer overflow
A vulnerability classified as critical has been found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the file /boafrm/formWlSiteSurvey of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6939?
CVE-2025-6939 is classified as a critical vulnerability.
What component is affected by CVE-2025-6939?
CVE-2025-6939 affects the HTTP POST Request Handler component in the TOTOLINK A3002RU.
What type of vulnerability is CVE-2025-6939?
CVE-2025-6939 is a buffer overflow vulnerability due to improper manipulation of the submit-url argument.
How can I mitigate CVE-2025-6939?
To mitigate CVE-2025-6939, it's recommended to update the firmware of the TOTOLINK A3002RU to the latest version provided by the vendor.
What impact does CVE-2025-6939 have on affected systems?
CVE-2025-6939 can lead to arbitrary code execution on affected systems due to the buffer overflow.