CVE-2025-4823: TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formReflashClientTbl submit-url buffer overflow
A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been rated as critical. Affected by this issue is the function submit-url of the file /boafrm/formReflashClientTbl of the component HTTP POST Request Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4823?
CVE-2025-4823 has been rated as critical.
Which devices are affected by CVE-2025-4823?
CVE-2025-4823 affects the TOTOLINK A702R, A3002R, and A3002RU devices.
How do I fix CVE-2025-4823?
To fix CVE-2025-4823, you should update your firmware to the latest version released by TOTOLINK.
What type of attack does CVE-2025-4823 facilitate?
CVE-2025-4823 can lead to buffer manipulation due to flaws in the HTTP POST request handler.
What component is vulnerable in CVE-2025-4823?
CVE-2025-4823 affects the function submit-url in the HTTP POST Request Handler of the affected devices.