CVE-2025-4833: TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formNtp buffer overflow
A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615 and classified as critical. This issue affects some unknown processing of the file /boafrm/formNtp of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4833?
CVE-2025-4833 is classified as a critical vulnerability.
Which devices are affected by CVE-2025-4833?
CVE-2025-4833 affects the TOTOLINK A702R, A3002R, and A3002RU devices.
How do I fix CVE-2025-4833?
To fix CVE-2025-4833, it is recommended to update the affected device firmware to the latest version provided by TOTOLINK.
What components are impacted by CVE-2025-4833?
CVE-2025-4833 impacts the HTTP POST Request Handler component of the affected devices.
What is the exploit mechanism for CVE-2025-4833?
The vulnerability in CVE-2025-4833 can be exploited through manipulation of the 'submit-url' argument in the '/boafrm/formNtp' file.