PT-2025-31027 · Totolink · Totolink X15
Panda_0X1
·
Published
2025-07-25
·
Updated
2025-08-01
·
CVE-2025-8244
Panda_0X1
·
Published
2025-07-25
·
Updated
2025-08-01
·
CVE-2025-8244
9.8
Critical
Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
**Name of the Vulnerable Software and Affected Versions:**
TOTOLINK X15 version 1.0.0-B20230714.1105
**Description:**
A critical vulnerability exists in the TOTOLINK X15 device. The vulnerability is related to a buffer overflow in the HTTP POST Request Handler component, specifically within the `/boafrm/formMapDelDevice` file. Manipulation of the `macstr` argument can trigger this overflow, potentially allowing for remote code execution or denial of service. The exploit for this issue has been publicly disclosed.
**Recommendations:**
TOTOLINK X15 version 1.0.0-B20230714.1105: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Command Injection