PT-2025-31027 · Totolink · Totolink X15

Panda_0X1

·

Published

2025-07-25

·

Updated

2025-08-01

·

CVE-2025-8244

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TOTOLINK X15 version 1.0.0-B20230714.1105
Description A critical vulnerability exists in the TOTOLINK X15 device. The issue is a buffer overflow within an unknown function of the HTTP POST Request Handler component, specifically in the file /boafrm/formMapDelDevice. Manipulation of the macstr argument can trigger this overflow, potentially leading to a denial of service or arbitrary code execution. The attack can be launched remotely. The exploit for this vulnerability has been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-09072
CVE-2025-8244

Affected Products

Totolink X15