CVE-2025-4831: TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formSiteSurveyProfile buffer overflow
A vulnerability, which was classified as critical, was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. This affects an unknown part of the file /boafrm/formSiteSurveyProfile of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4831?
CVE-2025-4831 has been classified as a critical vulnerability.
What components are affected by CVE-2025-4831?
CVE-2025-4831 affects the HTTP POST Request Handler in TOTOLINK A702R, A3002R, and A3002RU routers.
How do I fix CVE-2025-4831?
To fix CVE-2025-4831, users should update their firmware to the latest version provided by TOTOLINK.
What type of vulnerability is CVE-2025-4831?
CVE-2025-4831 involves improper handling of the submit-url argument within an HTTP POST Request.
What are the potential impacts of CVE-2025-4831?
CVE-2025-4831 could potentially allow an attacker to manipulate settings or gain unauthorized access to the affected devices.