CVE-2025-25610

CVSS 3.1 Score 8 of 10 (high)

Details

Published Feb 28, 2025
Updated: Mar 5, 2025
CWE ID 120

Summary

CVE-2025-25610 is a newly identified buffer overflow vulnerability affecting the TOTOlink A3002R V1.1.1-B20200824.0128. This issue is due to the inadequate validation of the static_gw parameter within the formIpv6Setup interface in the /bin/boa file. An attacker can potentially exploit this vulnerability by sending maliciously crafted data to the system, causing it to overflow the buffer and execute arbitrary code. This could lead to unauthorized access, data theft, or system crashes. Users are advised to update their TOTOlink devices to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share