A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101. It has been classified as problematic. This affects an unknown part of the file /boafrm/formFilter of the component HTTP POST Message Handler. The manipulation of the argument url leads to denial of service. The exploit has been disclosed to the public and may be used.
References
Link | Resource |
---|---|
https://github.com/d2pq/cve/blob/main/616/21.md | Exploit Third Party Advisory |
https://github.com/d2pq/cve/blob/main/616/21.md#poc | Exploit Third Party Advisory |
https://vuldb.com/?ctiid.313395 | Permissions Required Third Party Advisory VDB Entry |
https://vuldb.com/?id.313395 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.597688 | Third Party Advisory VDB Entry |
https://www.totolink.net/ | Product |
https://github.com/d2pq/cve/blob/main/616/21.md | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
25 Jun 2025, 20:14
Type | Values Removed | Values Added |
---|---|---|
First Time |
Totolink
Totolink n300rh Firmware Totolink n300rh |
|
References | () https://github.com/d2pq/cve/blob/main/616/21.md - Exploit, Third Party Advisory | |
References | () https://github.com/d2pq/cve/blob/main/616/21.md#poc - Exploit, Third Party Advisory | |
References | () https://vuldb.com/?ctiid.313395 - Permissions Required, Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?id.313395 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.597688 - Third Party Advisory, VDB Entry | |
References | () https://www.totolink.net/ - Product | |
CPE | cpe:2.3:o:totolink:n300rh_firmware:6.1c.1390_b20191101:*:*:*:*:*:*:* cpe:2.3:h:totolink:n300rh:-:*:*:*:*:*:*:* |
23 Jun 2025, 20:16
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/d2pq/cve/blob/main/616/21.md - | |
Summary |
|
21 Jun 2025, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-21 07:15
Updated : 2025-06-25 20:14
NVD link : CVE-2025-6401
Mitre link : CVE-2025-6401
CVE.ORG link : CVE-2025-6401
JSON object : View
Products Affected
totolink
- n300rh_firmware
- n300rh
CWE
CWE-404
Improper Resource Shutdown or Release