CVE-2025-4824: TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formWsc buffer overflow
A vulnerability classified as critical has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This affects an unknown part of the file /boafrm/formWsc of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4824?
CVE-2025-4824 is classified as a critical vulnerability.
What components are affected by CVE-2025-4824?
CVE-2025-4824 affects the HTTP POST Request Handler in the file /boafrm/formWsc.
How does CVE-2025-4824 affect the affected devices?
CVE-2025-4824 can cause a buffer overflow due to manipulation of the submit-url argument.
How do I fix CVE-2025-4824?
To fix CVE-2025-4824, upgrade your TOTOLINK A702R, A3002R, or A3002RU to the latest firmware version.
Which firmware versions are vulnerable to CVE-2025-4824?
Firmware version 3.0.0-B20230809.1615 of TOTOLINK A702R, A3002R, and A3002RU is vulnerable to CVE-2025-4824.