CVE-2025-25635: Totolink a3002r Firmware
High severity, CVSS 8.0. EPSS: 0.4% chance of exploitation in the next 30 days.
TOTOlink A3002R V1.1.1-B20200824.0128 contains a buffer overflow vulnerability. The vulnerability arises from the improper input validation of the pppoe_dns1 parameter in the formIpv6Setup interface of /bin/boa.
Affected products
- Totolink a3002r Firmware: version 1.1.1-b20200824.0128 only
Published 2025-02-28. Last modified 2026-06-17.