ID

VAR-202510-2144


CVE

CVE-2025-63461


TITLE

TOTOLINK A7000R urldecode function stack buffer overflow vulnerability

Trust: 0.6

sources: CNVD: CNVD-2025-27268

DESCRIPTION

Totolink A7000R v9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the ssid5g parameter in the urldecode function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. The TOTOLINK A7000R is a wireless router launched by TOTOLINK Electronics Co., Ltd. in China. It supports WiFi 7 technology and is suitable for home or small business network environments. This vulnerability stems from the fact that the ssid5g parameter in the urldecode function fails to properly validate the length of the input data

Trust: 1.44

sources: NVD: CVE-2025-63461 // CNVD: CNVD-2025-27268

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-27268

AFFECTED PRODUCTS

vendor:totolinkmodel:a7000rscope:eqversion:9.1.0u.6115_b20201022

Trust: 1.0

vendor:totolinkmodel:a7000r v9.1.0u.6115 b20201022scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2025-27268 // NVD: CVE-2025-63461

CVSS

SEVERITY

CVSSV2

CVSSV3

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2025-63461
value: HIGH

Trust: 1.0

CNVD: CNVD-2025-27268
value: HIGH

Trust: 0.6

CNVD: CNVD-2025-27268
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2025-63461
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2025-27268 // NVD: CVE-2025-63461

PROBLEMTYPE DATA

problemtype:CWE-121

Trust: 1.0

sources: NVD: CVE-2025-63461

EXTERNAL IDS

db:NVDid:CVE-2025-63461

Trust: 1.6

db:CNVDid:CNVD-2025-27268

Trust: 0.6

sources: CNVD: CNVD-2025-27268 // NVD: CVE-2025-63461

REFERENCES

url:https://github.com/0-fool/vulnbycola/blob/main/totolink/a7000/7/1.md

Trust: 1.6

sources: CNVD: CNVD-2025-27268 // NVD: CVE-2025-63461

SOURCES

db:CNVDid:CNVD-2025-27268
db:NVDid:CVE-2025-63461

LAST UPDATE DATE

2025-11-18T15:38:30.470000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-27268date:2025-11-07T00:00:00
db:NVDid:CVE-2025-63461date:2025-11-05T17:30:00.500

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-27268date:2025-11-07T00:00:00
db:NVDid:CVE-2025-63461date:2025-10-31T17:15:47.583