CVE-2025-25897
Published: 13 February 2025
Description
A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the 'ip' parameter at /userRpm/WanStaticIpV6CfgRpm.htm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.
Security Summary
CVE-2025-25897 is a buffer overflow vulnerability (CWE-787) discovered in TP-Link TL-WR841ND V11 routers. It affects the handling of the 'ip' parameter in the /userRpm/WanStaticIpV6CfgRpm.htm web endpoint. Published on 2025-02-13, the issue has a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), indicating high severity primarily due to its impact on availability.
Remote attackers can exploit this vulnerability without authentication, privileges, or user interaction. By sending a crafted packet to the vulnerable endpoint, they trigger the buffer overflow, causing a Denial of Service (DoS) that disrupts the router's functionality.
Additional technical details are available in the referenced document at https://github.com/2664521593/mycve/blob/main/TP-Link/BOF_in_TP-Link_TL-WR841ND-V11_3.pdf. No vendor advisories or patches are specified in the available information.
Details
- CWE(s)