CVE-2025-63469

7.5

Totolink · LR350

A stack overflow vulnerability in the Totolink LR350 router allows unauthenticated remote attackers to trigger a denial of service via a crafted request to the ssid parameter.

Executive summary

A stack-based buffer overflow in the Totolink LR350 router exposes the device to unauthenticated remote denial of service attacks.

Vulnerability

This vulnerability is a stack overflow located in the sub_421BAC function, which is triggered when an unauthenticated attacker sends a specially crafted ssid parameter to the device.

Business impact

Successful exploitation of this vulnerability results in a denial of service, rendering the network device unresponsive and potentially disrupting all dependent business communications and operations. With a CVSS score of 7.5, the vulnerability is classified as High severity, reflecting the ease of remote, unauthenticated exploitation that requires no user interaction.

Remediation

Immediate Action: Since no official patch is currently available, administrators should restrict management access to the device to trusted internal IP addresses only.

Proactive Monitoring: Monitor device logs for anomalous traffic patterns or repeated crashes and sudden service interruptions that may indicate an ongoing denial of service attempt.

Compensating Controls: Implement network-level ingress filtering and utilize a firewall to block unauthorized access to the router management interface from untrusted networks.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists as documented in the technical write-up provided by the researcher (referenced in the CVE record).

Analyst recommendation

Given the high CVSS score and the public availability of proof-of-concept code, this vulnerability poses a significant risk to network availability. Organizations utilizing the Totolink LR350 should prioritize isolating these devices from the public internet and continue to monitor the vendor portal for an official firmware update to address the stack overflow condition.

More Totolink CVEs

Sources