CVE-2025-4830: TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formSysCmd buffer overflow
A vulnerability, which was classified as critical, has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. Affected by this issue is some unknown functionality of the file /boafrm/formSysCmd of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4830?
CVE-2025-4830 is classified as a critical vulnerability affecting TOTOLINK A702R, A3002R, and A3002RU devices.
How do I fix CVE-2025-4830?
To fix CVE-2025-4830, update the firmware of your TOTOLINK A702R, A3002R, or A3002RU to the latest version.
What components are affected by CVE-2025-4830?
CVE-2025-4830 affects the HTTP POST Request Handler component in the file /boafrm/formSysCmd.
What products are impacted by CVE-2025-4830?
CVE-2025-4830 impacts the TOTOLINK A702R, A3002R, and A3002RU routers.
Is there any immediate action required for CVE-2025-4830?
Yes, users should immediately update to the latest firmware version to mitigate the security risk associated with CVE-2025-4830.