CVE-2025-55588

7.5

TOTOLINK · A3002R

A buffer overflow vulnerability exists in the TOTOLINK A3002R v4 router, allowing unauthenticated remote attackers to trigger a denial of service via the fw_ip parameter.

Executive summary

A buffer overflow vulnerability in the TOTOLINK A3002R v4 router allows unauthenticated remote attackers to cause a denial of service, presenting a significant risk to network availability.

Vulnerability

The device contains a buffer overflow vulnerability in the fw_ip parameter within the /boafrm/formPortFw endpoint. This flaw can be triggered by an unauthenticated attacker sending a crafted input to the vulnerable parameter.

Business impact

The successful exploitation of this vulnerability results in a denial of service, which renders the network device unresponsive. With a CVSS score of 7.5, this high-severity flaw can cause significant operational disruption by cutting off connectivity for users and services relying on the router, potentially leading to productivity loss and remediation costs.

Remediation

Immediate Action: Since no official patch is currently identified, administrators should restrict access to the management interface to trusted internal networks and disable remote administration features until the vendor releases a firmware update.

Proactive Monitoring: Monitor system logs for repeated crashes or unusual traffic patterns directed toward the /boafrm/formPortFw endpoint.

Compensating Controls: Implement a Web Application Firewall or an edge firewall rule to inspect and block malformed requests directed at the specified administrative endpoint.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists as documented in the research repository referenced by the CVE record.

Analyst recommendation

Given the availability of a public proof-of-concept and the potential for service disruption, this vulnerability poses a credible threat to the availability of the affected network infrastructure. Organizations using the TOTOLINK A3002R should prioritize isolating these devices from the public internet and closely monitor vendor support channels for the release of a security patch.

More TOTOLINK CVEs

Sources