CVE-2025-6148: TOTOLINK A3002RU HTTP POST Request formSysLog buffer overflow
A vulnerability was found in TOTOLINK A3002RU 3.0.0-B20230809.1615. It has been rated as critical. This issue affects some unknown processing of the file /boafrm/formSysLog of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6148?
CVE-2025-6148 has been rated as critical due to its potential impact.
How do I fix CVE-2025-6148?
To fix CVE-2025-6148, it is recommended to update the TOTOLINK A3002RU to the latest firmware version.
What components are affected by CVE-2025-6148?
CVE-2025-6148 affects the HTTP POST Request Handler, specifically the processing of the submit-url argument in the /boafrm/formSysLog file.
What kind of vulnerability is CVE-2025-6148?
CVE-2025-6148 is a buffer overflow vulnerability that can be exploited through crafted HTTP POST requests.
Which device does CVE-2025-6148 affect?
CVE-2025-6148 affects the TOTOLINK A3002RU router model.