CVE-2025-4834: TOTOLINK A702R/A3002R/A3002RU HTTP POST Request formSetLg buffer overflow
A vulnerability was found in TOTOLINK A702R, A3002R and A3002RU 3.0.0-B20230809.1615. It has been classified as critical. Affected is an unknown function of the file /boafrm/formSetLg of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4834?
CVE-2025-4834 is classified as a critical vulnerability.
Which devices are affected by CVE-2025-4834?
CVE-2025-4834 affects the TOTOLINK A702R, A3002R, and A3002RU routers.
How do I fix CVE-2025-4834?
To fix CVE-2025-4834, update the firmware of the affected TOTOLINK devices to the latest version.
What does CVE-2025-4834 exploit?
CVE-2025-4834 exploits an issue in the HTTP POST Request Handler component of the affected devices.
What is the potential impact of CVE-2025-4834?
The exploitation of CVE-2025-4834 can lead to a buffer overflow, compromising the affected device.