CVE-2025-6337: TOTOLINK A3002R/A3002RU HTTP POST Request formTmultiAP buffer overflow
A vulnerability was found in TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615/4.0.0-B20230531.1404. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formTmultiAP of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6337?
CVE-2025-6337 has been declared as a critical vulnerability.
How do I fix CVE-2025-6337?
To fix CVE-2025-6337, update TOTOLINK A3002R and A3002RU to the latest firmware version provided by the manufacturer.
What component is affected by CVE-2025-6337?
The component affected by CVE-2025-6337 is the HTTP POST Request Handler in the file /boafrm/formTmultiAP.
Which products are affected by CVE-2025-6337?
CVE-2025-6337 affects TOTOLINK A3002R and TOTOLINK A3002RU routers.
What kind of vulnerability is CVE-2025-6337?
CVE-2025-6337 is a security vulnerability that can be exploited through manipulation of HTTP POST requests.