CVE-2025-6401 is a low-severity denial of service vulnerability affecting TOTOLINK N300RH firmware version 6.1c.1390_B20191101. An authenticated attacker on the local network can trigger this vulnerability by manipulating the 'url' argument within the /boafrm/formFilter component's HTTP POST message handler. This issue has a CVSS score of 3.5 (LOW) and could lead to temporary service disruption. While public exploit details are available, there is no evidence of active exploitation, nor are there any known Metasploit or Nuclei modules. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.1c.1390_b20191101CPE matchmatch criteria | cpe:2.3:o:totolink:n300rh_firmware:6.1c.1390_b20191101:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.