CVE-2025-55586
7.5TOTOLINK · A3002R v4
TOTOLINK A3002R v4 contains a buffer overflow vulnerability in the url parameter of the formFilter function, allowing unauthenticated attackers to cause a Denial of Service.
Executive summary
A buffer overflow vulnerability in the TOTOLINK A3002R v4 router allows unauthenticated remote attackers to crash the device, resulting in a Denial of Service.
Vulnerability
This is a buffer overflow vulnerability occurring within the url parameter of the /boafrm/formFilter endpoint. The flaw allows an unauthenticated attacker to inject crafted input that triggers a service crash.
Business impact
The ability for an unauthenticated attacker to remotely induce a Denial of Service poses a significant operational risk, as it can disrupt network connectivity and critical services relying on the router. With a CVSS score of 7.5, this high severity vulnerability warrants immediate attention to prevent unauthorized service interruption and potential degradation of infrastructure availability.
Remediation
Immediate Action: Since no official patch is currently identified, administrators should restrict management access to the router to trusted internal networks only.
Proactive Monitoring: Monitor system logs for repeated crashes or unusual traffic patterns directed at the /boafrm/formFilter endpoint.
Compensating Controls: Implement firewall rules to block external access to the device management interface, thereby preventing remote exploitation attempts.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists as documented in the researcher write-up referenced in the CVE record.
Analyst recommendation
Given the availability of a public proof-of-concept and the potential for remote service disruption, this vulnerability presents a credible risk to network stability. Organizations using the affected hardware should prioritize isolating the device from the public internet and monitoring for any firmware updates from the vendor to resolve the underlying buffer overflow.