Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-28777 | A vulnerability classified as critical has been found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the file /boafrm/formWlSiteSurvey of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |
Mon, 07 Jul 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Totolink
Totolink a3002ru Totolink a3002ru Firmware |
|
| CPEs | cpe:2.3:h:totolink:a3002ru:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:a3002ru_firmware:3.0.0-b20230809.1615:*:*:*:*:*:*:* |
|
| Vendors & Products |
Totolink
Totolink a3002ru Totolink a3002ru Firmware |
Tue, 01 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 01 Jul 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability classified as critical has been found in TOTOLINK A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the file /boafrm/formWlSiteSurvey of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Title | TOTOLINK A3002RU HTTP POST Request formWlSiteSurvey buffer overflow | |
| Weaknesses | CWE-119 CWE-120 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-07-01T13:20:36.201Z
Reserved: 2025-06-30T17:59:19.603Z
Link: CVE-2025-6939
Updated: 2025-07-01T13:20:29.632Z
Status : Analyzed
Published: 2025-07-01T03:15:21.483
Modified: 2025-07-07T14:41:20.020
Link: CVE-2025-6939
No data.
OpenCVE Enrichment
Updated: 2025-07-06T22:16:25Z
EUVD