CVE-2025-6940: TOTOLINK A702R HTTP POST Request formParentControl buffer overflow
A vulnerability classified as critical was found in TOTOLINK A702R 4.0.0-B20230721.1521. Affected by this vulnerability is an unknown functionality of the file /boafrm/formParentControl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6940?
CVE-2025-6940 is classified as a critical severity vulnerability.
How do I fix CVE-2025-6940?
To fix CVE-2025-6940, update your TOTOLINK A702R to the latest firmware version provided by the vendor.
What component is affected in CVE-2025-6940?
CVE-2025-6940 affects the HTTP POST Request Handler within the file /boafrm/formParentControl.
What can attackers potentially do with CVE-2025-6940?
Attackers could manipulate the submit-url argument to exploit vulnerabilities in TOTOLINK A702R routers.
Which product versions are impacted by CVE-2025-6940?
CVE-2025-6940 impacts the TOTOLINK A702R version 4.0.0-B20230721.1521.