A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unknown function of the file /boafrm/formMapDelDevice of the component HTTP POST Request Handler. The manipulation of the argument macstr leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
References
Link | Resource |
---|---|
https://github.com/panda666-888/vuls/blob/main/totolink/x15/formMapDelDevice.md | Exploit Third Party Advisory |
https://vuldb.com/?ctiid.317832 | Permissions Required |
https://vuldb.com/?id.317832 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.622692 | Third Party Advisory VDB Entry |
https://www.totolink.net/ | Product |
Configurations
Configuration 1 (hide)
AND |
|
History
29 Jul 2025, 21:04
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:totolink:x15:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:x15_firmware:1.0.0-b20230714.1105:*:*:*:*:*:*:* |
|
First Time |
Totolink x15 Firmware
Totolink x15 Totolink |
|
CWE | CWE-77 | |
References | () https://github.com/panda666-888/vuls/blob/main/totolink/x15/formMapDelDevice.md - Exploit, Third Party Advisory | |
References | () https://vuldb.com/?ctiid.317832 - Permissions Required | |
References | () https://vuldb.com/?id.317832 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.622692 - Third Party Advisory, VDB Entry | |
References | () https://www.totolink.net/ - Product |
29 Jul 2025, 14:14
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
27 Jul 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-27 22:15
Updated : 2025-07-29 21:04
NVD link : CVE-2025-8244
Mitre link : CVE-2025-8244
CVE.ORG link : CVE-2025-8244
JSON object : View
Products Affected
totolink
- x15
- x15_firmware