TOTOLINK A3002RU HTTP POST Request formSysLog buffer overflow

CVE Details

Basic Information

Title TOTOLINK A3002RU HTTP POST Request formSysLog buffer overflow
Type cve
Published 2025-06-17T00:00:23.401Z
Last Seen

Product Information

Vendor TOTOLINK
Product A3002RU
Version 3.0.0-B20230809.1615

CVSS Information

Base Score 8.7 (HIGH)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A critical buffer overflow vulnerability exists in the TOTOLINK A3002RU router’s HTTP POST request handler, specifically in the formSysLog file. This allows remote attackers to execute arbitrary code by manipulating the submit-url argument. The vulnerability has been publicly disclosed and may be actively exploited.
AI Severity Critical
Vendor TOTOLINK
Product A3002RU
Affected Version 3.0.0-B20230809.1615

Affected Products

  • TOTOLINK A3002RU 3.0.0-B20230809.1615

Additional Information

CVE List
CWE List CWE-120, CWE-119
Bulletin Family

Description

A vulnerability was found in TOTOLINK A3002RU 3.0.0-B20230809.1615. It has been rated as critical. This issue affects some unknown processing of the file /boafrm/formSysLog of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.