CVE-2025-4832: TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formDosCfg buffer overflow
A vulnerability has been found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formDosCfg of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4832?
CVE-2025-4832 is classified as a critical vulnerability.
How do I fix CVE-2025-4832?
To mitigate CVE-2025-4832, update the firmware of the affected TOTOLINK A702R, A3002R, and A3002RU devices to the latest version.
What components are affected by CVE-2025-4832?
CVE-2025-4832 affects the HTTP POST Request Handler in the file /boafrm/formDosCfg.
What are the affected devices for CVE-2025-4832?
The affected devices for CVE-2025-4832 are TOTOLINK A702R, A3002R, and A3002RU routers.
What type of attack does CVE-2025-4832 enable?
CVE-2025-4832 allows for manipulation of the submit-url argument, potentially leading to denial of service.