CVE-2025-4729: TOTOLINK A3002R/A3002RU HTTP POST Request formMapDelDevice command injection
A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMapDelDevice of the component HTTP POST Request Handler. The manipulation of the argument macstr leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4729?
CVE-2025-4729 is classified as a critical vulnerability affecting TOTOLINK A3002R and A3002RU devices.
How do I fix CVE-2025-4729?
To mitigate CVE-2025-4729, update the firmware of your TOTOLINK A3002R or A3002RU device to the latest version provided by the vendor.
Which devices are affected by CVE-2025-4729?
CVE-2025-4729 affects TOTOLINK A3002R and A3002RU devices running the firmware version 3.0.0-B20230809.1615.
What component is vulnerable in CVE-2025-4729?
CVE-2025-4729 impacts the HTTP POST Request Handler component of the affected devices.
What kind of attack can exploit CVE-2025-4729?
CVE-2025-4729 can be exploited through manipulation of specific arguments in the HTTP POST requests to the affected devices.