CVE-2025-63464
7.5Totolink · LR350
Totolink LR350 v9.3.5u.6369_B20220309 contains a stack overflow vulnerability in the ssid parameter, allowing unauthenticated remote attackers to cause a denial of service.
Executive summary
A stack overflow vulnerability in the Totolink LR350 router allows unauthenticated remote attackers to trigger a denial of service condition.
Vulnerability
This is a stack overflow vulnerability occurring within the sub_42396C function when processing the ssid parameter. The vulnerability is reachable by an unauthenticated attacker via a crafted network request.
Business impact
Successful exploitation of this flaw results in a denial of service, effectively rendering the network device unresponsive. With a CVSS score of 7.5, the vulnerability poses a high risk to operational continuity, as attackers can disrupt critical network connectivity without requiring prior authentication or user interaction.
Remediation
Immediate Action: Contact the vendor to confirm the availability of a firmware update or security patch for the LR350 model, and apply it immediately if provided.
Proactive Monitoring: Monitor network device logs for anomalous traffic patterns or sudden service restarts that may indicate repeated attempts to trigger the crash.
Compensating Controls: Deploy a network firewall or intrusion prevention system to filter or restrict access to the device management interface from untrusted networks.
Exploitation status
Public Exploit Available: Yes, a proof of concept is available via the technical write-up referenced in the CVE record.
Analyst recommendation
Given the high CVSS severity and the presence of a public proof of concept, this vulnerability requires prompt attention to ensure network stability. Administrators should prioritize identifying vulnerable units within their environment and apply vendor-supplied firmware updates as soon as they become available to eliminate the risk of service disruption.