Buffer Overflow Vulnerability in TOTOLINK Products Impacting Remote Access
CVE-2025-4831

8.7HIGH

Key Information:

Vendor

Totolink

Vendor
CVE Published:
17 May 2025

What is CVE-2025-4831?

A vulnerability has been identified in TOTOLINK A702R, A3002R, and A3002RU products that allows for remote exploitation via the HTTP POST Request Handler component. Specifically, manipulation of the 'submit-url' argument can lead to a buffer overflow, potentially compromising the affected device. With public disclosure of the exploit, it is crucial for organizations using these devices to implement necessary security measures to mitigate potential risks.

Affected Version(s)

A3002R 3.0.0-B20230809.1615

A3002RU 3.0.0-B20230809.1615

A702R 3.0.0-B20230809.1615

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

BabyShark (VulDB User)
.
CVE-2025-4831 : Buffer Overflow Vulnerability in TOTOLINK Products Impacting Remote Access