CVE-2025-25524 Details
Description
Buffer overflow vulnerability in TOTOLink X6000R routers V9.4.0cu.652_B20230116 due to the lack of length verification, which is related to the addition of Wi-Fi filtering rules. Attackers who successfully exploit this vulnerability can cause the remote target device to crash or execute arbitrary commands.
A buffer overflow vulnerability has been identified in TOTOLink X6000R routers running version V9.4.0cu.652_B20230116. The vulnerability arises from inadequate length verification when adding Wi-Fi filtering rules. Attackers exploiting this issue can cause the device to crash or execute arbitrary commands.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/XiaoCurry/ce1f80afd2d8be8ca543437f16eae96b | [email protected] | Broken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| totolink x6000r firmware | 9.4.0cu.652_b20230116 |
CPE
Remediation
| |
| totolink x6000r | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2025 | Initial Analysis | [email protected] |
| Feb 13, 2025 | CVE Modified | CISA-ADP |
| Feb 11, 2025 | New CVE Received | [email protected] |