CVE-2025-8140: TOTOLINK A702R HTTP POST Request formWlanMultipleAP buffer overflow
A vulnerability was found in TOTOLINK A702R 4.0.0-B20230721.1521. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formWlanMultipleAP of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8140?
CVE-2025-8140 has been declared as critical.
What component is affected by CVE-2025-8140?
CVE-2025-8140 affects the HTTP POST Request Handler of the TOTOLINK A702R.
How does CVE-2025-8140 exploit occur?
The exploitation of CVE-2025-8140 occurs through the manipulation of the argument submit-url.
What are the potential consequences of exploiting CVE-2025-8140?
Exploiting CVE-2025-8140 can lead to a buffer overflow vulnerability.
What is the version of the affected product for CVE-2025-8140?
The affected product for CVE-2025-8140 is TOTOLINK A702R version 4.0.0-B20230721.1521.