CVE-2025-6163: TOTOLINK A3002RU HTTP POST Request formMultiAP buffer overflow
A vulnerability was found in TOTOLINK A3002RU 3.0.0-B20230809.1615 and classified as critical. Affected by this issue is some unknown functionality of the file /boafrm/formMultiAP of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6163?
CVE-2025-6163 is classified as critical due to its potential impact on affected devices.
How do I fix CVE-2025-6163?
To mitigate CVE-2025-6163, it is recommended to update the TOTOLINK A3002RU to the latest firmware version provided by the vendor.
What component is affected by CVE-2025-6163?
CVE-2025-6163 affects the HTTP POST Request Handler functionality of the file /boafrm/formMultiAP.
What type of vulnerability is CVE-2025-6163?
CVE-2025-6163 is a buffer overflow vulnerability that can be exploited through crafted HTTP POST requests.
Which product is impacted by CVE-2025-6163?
CVE-2025-6163 impacts the TOTOLINK A3002RU router.