CVE-2025-8137: TOTOLINK A702R HTTP POST Request formIpQoS buffer overflow
A vulnerability has been found in TOTOLINK A702R 4.0.0-B20230721.1521 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formIpQoS of the component HTTP POST Request Handler. The manipulation of the argument mac leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8137?
CVE-2025-8137 is classified as a critical vulnerability, indicating a severe risk to affected systems.
Which product is affected by CVE-2025-8137?
CVE-2025-8137 affects the TOTOLINK A702R device running version 4.0.0-B20230721.1521.
How do I fix CVE-2025-8137?
To remediate CVE-2025-8137, users should update to the latest firmware provided by TOTOLINK that addresses this vulnerability.
What is the nature of the vulnerability in CVE-2025-8137?
CVE-2025-8137 involves a buffer manipulation issue within the HTTP POST Request Handler related to the argument 'mac'.
What could be the consequences of exploiting CVE-2025-8137?
Exploitation of CVE-2025-8137 may lead to unauthorized access or denial of service, impacting the functionality of the affected device.