First published: Sun Apr 27 2025(Updated: )
A vulnerability, which was classified as critical, was found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the file /boafrm/formWdsEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Totolink N150RT-V2 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-3991 is classified as a critical severity vulnerability.
To fix CVE-2025-3991, users should update the TOTOLINK N150RT to the latest firmware version that addresses this vulnerability.
CVE-2025-3991 can lead to a buffer overflow due to the manipulation of the submit-url argument.
Yes, CVE-2025-3991 can be exploited remotely, allowing an attacker to initiate an attack without local access.
CVE-2025-3991 affects the /boafrm/formWdsEncrypt file in the TOTOLINK N150RT.