Buffer Overflow Vulnerability in TOTOLINK A3002R and A3002RU Products
CVE-2025-6337
Key Information:
Badges
What is CVE-2025-6337?
A vulnerability exists in the TOTOLINK A3002R and A3002RU routers, specifically within the HTTP POST Request Handler component, which can be exploited via manipulation of the 'submit-url' parameter. This flaw results in a buffer overflow condition that can be triggered remotely, potentially allowing an attacker to execute arbitrary code or perform unauthorized actions on the affected devices. Users are urged to take precautionary measures to mitigate any threats related to this exposure.
Affected Version(s)
A3002R 3.0.0-B20230809.1615
A3002R 4.0.0-B20230531.1404
A3002RU 3.0.0-B20230809.1615
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved