Buffer Overflow Vulnerability in TOTOLINK A702R and A3002R Series Routers
CVE-2025-4833

8.7HIGH

Key Information:

Vendor

Totolink

Vendor
CVE Published:
17 May 2025

What is CVE-2025-4833?

A vulnerability has been identified in the processing of HTTP POST requests for the TOTOLINK A702R and A3002R series routers. This issue arises from insecure handling of the submit-url argument within the formNtp file, potentially leading to a buffer overflow situation. Attackers can exploit this vulnerability remotely, risking the integrity and security of networked devices. Immediate action is advised to mitigate exposure and secure affected systems.

Affected Version(s)

A3002R 3.0.0-B20230809.1615

A3002RU 3.0.0-B20230809.1615

A702R 3.0.0-B20230809.1615

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

DaddyShark (VulDB User)
.
CVE-2025-4833 : Buffer Overflow Vulnerability in TOTOLINK A702R and A3002R Series Routers