CVE-2025-55587
7.5TOTOLINK · A3002R v4
A buffer overflow vulnerability exists in the TOTOLINK A3002R v4 hostname parameter, allowing unauthenticated attackers to trigger a denial of service via crafted input.
Executive summary
A buffer overflow flaw in the TOTOLINK A3002R v4 router allows unauthenticated attackers to crash the device, resulting in a denial of service.
Vulnerability
The vulnerability is a buffer overflow occurring in the hostname parameter within the /boafrm/formMapDelDevice endpoint. It allows an unauthenticated attacker to send malicious input to the device, leading to a service crash.
Business impact
Successful exploitation of this vulnerability results in a denial of service, rendering the affected network device unresponsive. With a CVSS score of 7.5, this high severity issue poses a significant risk to operational continuity, as attackers can disrupt network connectivity without requiring any prior authentication.
Remediation
Immediate Action: Since a vendor-provided patch is currently unknown, administrators should restrict management interface access to trusted IP addresses only.
Proactive Monitoring: Monitor device logs for unusual spikes in traffic directed at the /boafrm/formMapDelDevice endpoint or unexpected system reboots.
Compensating Controls: Deploy firewall rules to block unsolicited inbound traffic to the device management interface, effectively isolating the vulnerable endpoint from external access.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the referenced GitHub repository.
Analyst recommendation
Given the public availability of a proof-of-concept, this vulnerability presents a credible risk to network availability. Organizations using the TOTOLINK A3002R v4 should immediately implement network-level access controls to prevent unauthorized access to the management interface until a firmware update is released by the manufacturer.