Buffer Overflow Vulnerability in TOTOLINK A702R Router
CVE-2025-6825
Key Information:
Badges
What is CVE-2025-6825?
A vulnerability identified in the TOTOLINK A702R router's HTTP POST Request Handler allows an attacker to exploit the /boafrm/formWlSiteSurvey component. By manipulating the 'submit-url' argument, a buffer overflow can occur, which may lead to unauthorized access or control of the affected system. This vulnerability can be exploited remotely, emphasizing the need for immediate attention and patching by users of the affected version up to 4.0.0-B20230721.1521.
Affected Version(s)
A702R 4.0.0-B20230721.1521
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved