CVE-2025-6164: TOTOLINK A3002R HTTP POST Request formMultiAP buffer overflow
A vulnerability was found in TOTOLINK A3002R 4.0.0-B20230531.1404. It has been classified as critical. This affects an unknown part of the file /boafrm/formMultiAP of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6164?
CVE-2025-6164 has been classified as critical.
How does CVE-2025-6164 affect the TOTOLINK A3002R?
CVE-2025-6164 affects the HTTP POST Request Handler of the TOTOLINK A3002R, allowing a buffer overflow vulnerability.
What component is impacted by CVE-2025-6164?
CVE-2025-6164 impacts the file /boafrm/formMultiAP in the component related to HTTP POST requests.
What can lead to a buffer overflow in CVE-2025-6164?
The manipulation of the argument submit-url leads to a buffer overflow in CVE-2025-6164.
How can I mitigate CVE-2025-6164?
To mitigate CVE-2025-6164, it is recommended to apply any available firmware updates from TOTOLINK for the A3002R.