CNNVD-202507-3168 Information

CNNVD ID

CNNVD-202507-3168

CVE-2025-8137

  • CNNVD Published: 2025-07-25

Description (Chinese)

TOTOLINK A702r是中国吉翁电子(TOTOLINK)公司的一款路由器设备。 TOTOLINK A702R 4.0.0-B20230721.1521版本存在安全漏洞,该漏洞源于HTTP POST请求处理组件中文件/boafrm/formIpQoS对参数mac的错误操作导致缓冲区溢出。

Description (English)

TOTOLINK A702r is a router equipment of the Chinese company TOTOLINK. TOTOLINK A702R 4.0.0-B202300721.1521 contains a security loophole resulting from the error in the processing of the document/boafrm/formIpQos against parameter Mac in the HTTTP POST request.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

吉翁电子

Published

2025-07-25

Last Modified

2026-02-24

References

https://github.com/panda666-888/vuls/blob/main/totolink/a702r/formIpQoS.md https://vuldb.com/?ctiid.317533 https://vuldb.com/?id.317533 https://vuldb.com/?submit.620483 https://www.totolink.net/ https://access.redhat.com/security/cve/cve-2025-8137

Share on: