CVE-2025-63465
7.5Totolink · LR350
A stack overflow vulnerability in the Totolink LR350 allows unauthenticated attackers to trigger a Denial of Service through a crafted ssid parameter request.
Executive summary
A critical stack overflow vulnerability in the Totolink LR350 router allows unauthenticated remote attackers to cause a complete system denial of service.
Vulnerability
The device contains a stack overflow vulnerability within the sub_422880 function, specifically triggered by the ssid parameter. This flaw allows an unauthenticated, remote attacker to crash the device service via a specially crafted network request.
Business impact
The vulnerability carries a CVSS score of 7.5, reflecting a significant risk to service availability. Successful exploitation results in a Denial of Service, which can disrupt critical network operations, remote connectivity, and business continuity for organizations relying on this hardware.
Remediation
Immediate Action: Since a vendor-provided patch is currently unknown, administrators should restrict network access to the management interface and block untrusted external traffic from reaching the device.
Proactive Monitoring: Monitor device uptime logs and network traffic for repeated, abnormally large requests targeting the router configuration parameters.
Compensating Controls: Deploy a network-level firewall or intrusion prevention system to filter and drop malformed packets or suspicious requests directed at the device's management functions.
Exploitation status
Public Exploit Available: Yes, a proof of concept is available via the researcher's write-up hosted on GitHub.
Analyst recommendation
Given the availability of a public proof of concept and the potential for total service disruption, users of the Totolink LR350 should prioritize isolating the device from the public internet. If the device is required for remote operations, implement strict access control lists to limit management access to known, trusted IP addresses while awaiting further guidance or firmware updates from the vendor.