Severity
8.7HIGH
EPSS
0.6%
top 31.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 5

Description

A vulnerability, which was classified as critical, was found in TOTOLINK N302R Plus up to 3.4.0-B20201028. Affected is an unknown function of the file /boafrm/formPortFw of the component HTTP POST Request Handler. The manipulation of the argument service_type leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages2 packages

NVDtotolink/n302r_plus_firmware< 3.4.0-b20201028
CVEListV5totolink/n302r_plus3.4.0-B20201028

🔴Vulnerability Details

2
CVEList
TOTOLINK N302R Plus HTTP POST Request formPortFw buffer overflow2025-06-05
GHSA
GHSA-fqr7-x5vp-p2wq: A vulnerability, which was classified as critical, was found in TOTOLINK N302R Plus up to 32025-06-05
CVE-2025-5671 (HIGH CVSS 8.7) | A vulnerability | cvebase.io