CVE-2025-6147: TOTOLINK A702R HTTP POST Request formSysLog buffer overflow
A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formSysLog of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6147?
CVE-2025-6147 has been declared as critical.
How does CVE-2025-6147 affect the TOTOLINK A702R?
CVE-2025-6147 affects the HTTP POST Request Handler component by leading to a buffer overflow through manipulation of the submit-url argument.
What is the attack vector for CVE-2025-6147?
The attack vector for CVE-2025-6147 involves sending a specially crafted HTTP POST request that exploits the buffer overflow vulnerability.
What should I do if I am using TOTOLINK A702R and CVE-2025-6147 is present?
If you are using TOTOLINK A702R, it's critical to apply any available security patches or updates from the vendor to mitigate CVE-2025-6147.
Is there a workaround for CVE-2025-6147?
Disabling the affected HTTP POST functionality may serve as a temporary workaround for CVE-2025-6147 until a patch is applied.