CVE Details
Basic Information
| Title | TOTOLINK N302R Plus HTTP POST Request formFilter buffer overflow |
|---|---|
| Type | cve |
| Published | 2025-06-05T17:31:10.945Z |
| Last Seen |
Product Information
| Vendor | TOTOLINK |
|---|---|
| Product | N302R Plus |
| Version | 3.4.0-B20201028 |
CVSS Information
| Base Score | 8.7 (HIGH) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A critical buffer overflow vulnerability in the HTTP POST request handler of TOTOLINK N302R Plus routers allows remote attackers to execute arbitrary code, potentially leading to full system compromise. |
|---|---|
| AI Severity | High |
| Vendor | TOTOLINK |
| Product | N302R Plus |
| Affected Version | 3.4.0-B20201028 |
Affected Products
- TOTOLINK N302R Plus 3.4.0-B20201028
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-120, CWE-119 |
| Bulletin Family |
References
Description
A vulnerability has been found in TOTOLINK N302R Plus up to 3.4.0-B20201028 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formFilter of the component HTTP POST Request Handler. The manipulation of the argument url leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.