CVE-2025-8139: TOTOLINK A702R HTTP POST Request formPortFw buffer overflow
A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521. It has been classified as critical. This affects an unknown part of the file /boafrm/formPortFw of the component HTTP POST Request Handler. The manipulation of the argument servicetype leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8139?
CVE-2025-8139 is classified as critical due to its potential to exploit a buffer overflow.
How does CVE-2025-8139 affect the TOTOLINK A702R?
CVE-2025-8139 affects the HTTP POST Request Handler component, allowing manipulation of the argument service_type.
What are the potential impacts of CVE-2025-8139?
The manipulation allowed by CVE-2025-8139 can lead to remote code execution or denial of service.
How do I fix CVE-2025-8139?
To mitigate CVE-2025-8139, update the TOTOLINK A702R firmware to the latest version provided by the vendor.
When was CVE-2025-8139 disclosed?
CVE-2025-8139 was disclosed as a vulnerability in TOTOLINK A702R with the firmware version 4.0.0-B20230721.1521.