CVE-2025-63468
7.5Totolink · LR350
Totolink LR350 v9.3.5u.6369_B20220309 contains a stack overflow vulnerability in the http_host parameter, allowing unauthenticated attackers to trigger a denial of service.
Executive summary
A critical stack overflow vulnerability in the Totolink LR350 router allows unauthenticated remote attackers to crash the device, leading to a complete denial of service.
Vulnerability
The device is susceptible to a stack-based buffer overflow triggered by a malformed http_host parameter within the sub_426EF8 function. This flaw is exploitable by an unauthenticated attacker via a crafted network request.
Business impact
The exploitation of this vulnerability results in a denial of service, rendering the affected network infrastructure unreachable. With a CVSS score of 7.5, the risk is classified as High due to the lack of required authentication and the ease of network-based exploitation. Business operations relying on this hardware for connectivity will face significant downtime until the device is manually recovered.
Remediation
Immediate Action: Since an official patch is currently unknown, users should immediately isolate the affected LR350 routers from the public internet and restrict access to trusted administrative networks.
Proactive Monitoring: Security teams should monitor device logs for repeated crashes or unusual request patterns targeting the HTTP interface.
Compensating Controls: Deploy a Web Application Firewall or network access control list to filter and block malformed HTTP requests sent to the device management interface.
Exploitation status
Public Exploit Available: Yes — a published proof-of-concept exists, as documented in the referenced security researcher's write-up.
Analyst recommendation
Given the public availability of proof-of-concept code and the high potential for service disruption, immediate network-level mitigation is required. Administrators must restrict management access to the device until the manufacturer releases a firmware update that addresses the stack overflow in the identified function.