CVE-2025-4733: TOTOLINK A3002R/A3002RU HTTP POST Request formIpQoS buffer overflow
A vulnerability, which was classified as critical, has been found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615. This issue affects some unknown processing of the file /boafrm/formIpQoS of the component HTTP POST Request Handler. The manipulation of the argument mac leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4733?
CVE-2025-4733 is classified as a critical vulnerability.
How do I fix CVE-2025-4733?
To fix CVE-2025-4733, update the firmware of the TOTOLINK A3002R or A3002RU to the latest version provided by the manufacturer.
What components are affected by CVE-2025-4733?
CVE-2025-4733 affects the HTTP POST Request Handler processing the file /boafrm/formIpQoS.
What is the risk associated with CVE-2025-4733?
The manipulation of the 'mac' argument in CVE-2025-4733 could lead to unauthorized access or configuration changes.
Which TOTOLINK devices are impacted by CVE-2025-4733?
CVE-2025-4733 impacts the TOTOLINK A3002R and A3002RU devices.