CVE-2025-45861CRITICAL 9.8EPSS p40.6%

CVE-2025-45861CVE-2025-45861

Description

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the formDnsv6 interface.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.53% probability of exploitation · percentile 40.6% · 2026-06-18T12:00:27Z
Published2025-05-13
Last modified2025-05-15

Underlying weaknesses· 1

CWE-120

References

  1. https://github.com/Jiangxiazhe/IOT_hack/blob/main/TOTOLINK/A3002R/3/overflow.md
  2. https://www.totolink.net/home/menu/detail/menu_listtpl/download/id/258/ids/36.html

1

TypeTargetConfidenceTier
WeaknessBuffer Copy without Checking Size of Input ('Classic Buffer Overflow')cwe-1200%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-45865
CVE
CVE-2026-26731
CVE
CVE-2025-25635
CVE
CVE-2025-25609
CVE
CVE-2025-25610
CVE
CVE-2025-45863
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.