Buffer Overflow Vulnerability in TOTOLINK A702R Product
CVE-2025-9782
Key Information:
Badges
What is CVE-2025-9782?
A remote code execution vulnerability exists in the TOTOLINK A702R router, specifically in the function sub_4466F8 within the file /boafrm/formOneKeyAccessButton. This vulnerability arises from insufficient validation of user input, allowing attackers to manipulate the submit-url argument, leading to a buffer overflow. As a result, this can compromise the integrity and functionality of the device, potentially granting unauthorized access. The exploit for this vulnerability has been publicly disclosed, emphasizing the urgency for patching and securing affected versions to protect against potential attacks.
Affected Version(s)
A702R 4.0.0-B20211108.1423
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved