CVE-2025-4825: TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formDMZ buffer overflow
A vulnerability classified as critical was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This vulnerability affects unknown code of the file /boafrm/formDMZ of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4825?
CVE-2025-4825 is classified as a critical vulnerability.
What products are affected by CVE-2025-4825?
CVE-2025-4825 affects the TOTOLINK A702R, A3002R, and A3002RU devices.
How do I fix CVE-2025-4825?
To fix CVE-2025-4825, update the firmware of the affected TOTOLINK devices to the latest version available.
What type of vulnerability is CVE-2025-4825?
CVE-2025-4825 is a buffer overflow vulnerability found in the HTTP POST Request Handler.
What is the impact of CVE-2025-4825?
CVE-2025-4825 can lead to unauthorized code execution due to buffer overflow.