PT-2025-31027 · Totolink · Totolink X15

Panda_0X1

·

Published

2025-07-25

·

Updated

2025-08-01

·

CVE-2025-8244

CVSS v3.1
9.8
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

**Name of the Vulnerable Software and Affected Versions:**

TOTOLINK X15 version 1.0.0-B20230714.1105

**Description:**

A critical vulnerability exists in the TOTOLINK X15 device. The vulnerability is related to a buffer overflow in the HTTP POST Request Handler component, specifically within the `/boafrm/formMapDelDevice` file. Manipulation of the `macstr` argument can trigger this overflow, potentially allowing for remote code execution or denial of service. The exploit for this issue has been publicly disclosed.

**Recommendations:**

TOTOLINK X15 version 1.0.0-B20230714.1105: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-09072
CVE-2025-8244

Affected Products

Totolink X15