CVE-2025-4829: TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formStats sub_40BE30 buffer overflow
A vulnerability classified as critical was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. Affected by this vulnerability is the function sub40BE30 of the file /boafrm/formStats of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4829?
CVE-2025-4829 is classified as a critical vulnerability.
What devices are affected by CVE-2025-4829?
The vulnerability affects TOTOLINK A702R, A3002R, and A3002RU routers running firmware version 3.0.0-B20230809.1615.
How does CVE-2025-4829 impact affected devices?
CVE-2025-4829 impacts the HTTP POST Request Handler function, allowing potential malicious manipulation of data.
How do I fix CVE-2025-4829?
To fix CVE-2025-4829, update your affected TOTOLINK device to the latest available firmware version.
What should I do if I cannot mitigate CVE-2025-4829 quickly?
If you cannot immediately mitigate CVE-2025-4829, consider isolating affected devices from your network.