CVE-2025-4827: TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formSaveConfig buffer overflow
A vulnerability, which was classified as critical, was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. Affected is an unknown function of the file /boafrm/formSaveConfig of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4827?
CVE-2025-4827 is classified as a critical vulnerability.
Which devices are affected by CVE-2025-4827?
CVE-2025-4827 affects the TOTOLINK A702R, A3002R, and A3002RU routers.
How do I fix CVE-2025-4827?
To fix CVE-2025-4827, update the firmware of the affected TOTOLINK devices to the latest version.
What component is vulnerable in CVE-2025-4827?
The vulnerability in CVE-2025-4827 is present in the HTTP POST Request Handler of the file /boafrm/formSaveConfig.
What type of attack does CVE-2025-4827 allow?
CVE-2025-4827 allows for manipulation of the submit-url argument, potentially leading to unauthorized access.