CVE-2025-3991: TOTOLINK N150RT formWdsEncrypt buffer overflow
A vulnerability, which was classified as critical, was found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the file /boafrm/formWdsEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3991?
CVE-2025-3991 is classified as a critical severity vulnerability.
How do I fix CVE-2025-3991?
To fix CVE-2025-3991, users should update the TOTOLINK N150RT to the latest firmware version that addresses this vulnerability.
What effect does CVE-2025-3991 have on the TOTOLINK N150RT?
CVE-2025-3991 can lead to a buffer overflow due to the manipulation of the submit-url argument.
Can CVE-2025-3991 be exploited remotely?
Yes, CVE-2025-3991 can be exploited remotely, allowing an attacker to initiate an attack without local access.
What part of the TOTOLINK N150RT is affected by CVE-2025-3991?
CVE-2025-3991 affects the /boafrm/formWdsEncrypt file in the TOTOLINK N150RT.