cbcvebase.
CVE-2025-6393
published 2025-06-21

CVE-2025-6393: A vulnerability was found in TOTOLINK A702R, A3002R, A3002RU and EX1200T 3.0.0-B20230809.1615/4.0.0-B20230531.1404/4.0.0-B20230721.1521/4.1.2cu.5232_B20210713…

high7.4CVSS 4.0
AVNACLATNPRLUINVCHVIHVAHSCNSINSANEPCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
A vulnerability was found in TOTOLINK A702R, A3002R, A3002RU and EX1200T 3.0.0-B20230809.1615/4.0.0-B20230531.1404/4.0.0-B20230721.1521/4.1.2cu.5232_B20210713. It has been classified as critical. Affected is an unknown function of the file /boafrm/formIPv6Addr of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Affected

20 ranges
VendorProductVersion rangeFixed in
totolinka3002r
totolinka3002r
totolinka3002r
totolinka3002r
totolinka3002r_firmware
totolinka3002ru
totolinka3002ru
totolinka3002ru
totolinka3002ru
totolinka3002ru_firmware
totolinka702r
totolinka702r
totolinka702r
totolinka702r
totolinka702r_firmware
totolinkex1200t
totolinkex1200t
totolinkex1200t
totolinkex1200t
totolinkex1200t_firmware