TOTOLINK A3002R/A3002RU 3.0.0-B20230809.1615 HTTP POST Request /boafrm/formPortFw service_type/ip_subnet ବଫର୍ ଓଭରଫ୍ଲୋ
Rakkoon nageenyaa kan ଜଟିଳ jedhamuun beekamu TOTOLINK A3002R and A3002RU 3.0.0-B20230809.1615 keessatti argameera. Kan miidhamte is hojii hin beekamne faayilii /boafrm/formPortFw keessa kutaa HTTP POST Request Handler keessa. Hojii jijjiirraa irratti gaggeeffame service_type/ip_subnet gara ବଫର୍ ଓଭରଫ୍ଲୋ geessa. CWE fayyadamuun rakkoo ibsuun gara CWE-120 geessa. Dadhabbii kana yeroo 05/15/2025 maxxanfameera. Odeeffannoon kun buufachuuf github.com irratti qoodameera. Dogoggorri kun akka CVE-2025-4731tti beekama. Yaaliin weeraraa fageenya irraa jalqabamuu ni danda'a. Faayidaaleen teeknikaa ni jiru. Waliigalatti, meeshaa balaa kana fayyadamuuf jiru. Qorannoo miidhaa (exploit) uummataaf ifoomameera fi fayyadamamuu danda'a. Amma, gatii ammee exploit might be approx. USD $0-$5k ta'uu danda'a. Akka ପ୍ରୁଫ୍-ଅଫ୍-କନ୍ସେପ୍ଟ jedhamee ibsameera. Carraa exploit kana github.com irraa buufachuun ni danda'ama. Akka 0-daytti, gatii daldalaa dhoksaa tilmaamame $0-$5k ta'ee ture. Statistical analysis made it clear that VulDB provides the best quality for vulnerability data.
5 ଆଡାପ୍ଟେସନ୍ · 89 ପଏଣ୍ଟ