CVE-2025-4826: TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formWirelessTbl buffer overflow
A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This issue affects some unknown processing of the file /boafrm/formWirelessTbl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4826?
CVE-2025-4826 is classified as a critical vulnerability in TOTOLINK routers.
How do I fix CVE-2025-4826?
To fix CVE-2025-4826, update your TOTOLINK A702R, A3002R, or A3002RU firmware to the latest version released by the vendor.
What products are affected by CVE-2025-4826?
CVE-2025-4826 affects TOTOLINK models A702R, A3002R, and A3002RU.
What type of vulnerability is CVE-2025-4826?
CVE-2025-4826 is a vulnerability related to the HTTP POST Request Handler on affected TOTOLINK devices.
What are the potential risks associated with CVE-2025-4826?
Exploiting CVE-2025-4826 could allow attackers to manipulate sensitive settings on affected TOTOLINK routers.