MEDIUM
TOTOLINK N300RH HTTP POST Message formFilter denial of service
Published Jun 21, 2025
5.1
MEDIUMCVSS 4.0
EPSS 0.55%
Description
A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101. It has been classified as problematic. This affects an unknown part of the file /boafrm/formFilter of the component HTTP POST Message Handler. The manipulation of the argument url leads to denial of service. The exploit has been disclosed to the public and may be used.
Affected products
-
- Version 6.1c.1390_B20191101StatusaffectedConstraints-
- Version
AND
- 6.1c.1390_b20191101
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-18807 Advisory
- https://github.com/d2pq/cve/blob/main/616/21.md exploitrelatedThird Party Advisory
- https://github.com/d2pq/cve/blob/main/616/21.md#poc exploitThird Party Advisory
- https://vuldb.com/?ctiid.313395 signaturepermissions-requiredPermissions RequiredThird Party AdvisoryVDB Entry
- https://vuldb.com/?id.313395 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.597688 third-party-advisoryThird Party AdvisoryVDB Entry
- https://www.totolink.net/ product
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-18807 | Advisory | |
| https://github.com/d2pq/cve/blob/main/616/21.md | exploitrelatedThird Party Advisory | |
| https://github.com/d2pq/cve/blob/main/616/21.md#poc | exploitThird Party Advisory | |
| https://vuldb.com/?ctiid.313395 | signaturepermissions-requiredPermissions RequiredThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?id.313395 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.597688 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://www.totolink.net/ | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Jun 21, 2025
Updated Jun 23, 2025
Reserved Jun 20, 2025
Link CVE-2025-6401
CISA Vulnrichment
Updated Jun 23, 2025
ENISA EUVD
EUVD-2025-18807 Assigner VulDB
Published Jun 21, 2025
Updated Jun 23, 2025
Exploited since n/a
Link EUVD-2025-18807