CVE-2025-5671: TOTOLINK N302R Plus HTTP POST Request formPortFw buffer overflow
A vulnerability, which was classified as critical, was found in TOTOLINK N302R Plus up to 3.4.0-B20201028. Affected is an unknown function of the file /boafrm/formPortFw of the component HTTP POST Request Handler. The manipulation of the argument servicetype leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5671?
CVE-2025-5671 is classified as a critical vulnerability.
How do I fix CVE-2025-5671?
To fix CVE-2025-5671, update the TOTOLINK N302R Plus firmware to a version later than 3.4.0-B20201028.
What components are affected by CVE-2025-5671?
CVE-2025-5671 affects the HTTP POST Request Handler, specifically the function related to the '/boafrm/formPortFw' file.
What kind of vulnerability is CVE-2025-5671?
CVE-2025-5671 is a buffer overflow vulnerability caused by manipulation of the 'service_type' argument.
Which devices are impacted by CVE-2025-5671?
Devices affected by CVE-2025-5671 are the TOTOLINK N302R Plus models running firmware version up to 3.4.0-B20201028.