CVE Details
Basic Information
| Title |
TOTOLINK X15 formMapReboot stack-based overflow |
| Type |
cve |
| Published |
2025-06-03T14:31:07.149Z |
| Last Seen |
|
Product Information
| Vendor |
TOTOLINK |
| Product |
X15 |
| Version |
1.0.0-B20230714.1105 |
CVSS Information
| Base Score |
8.7 (HIGH) |
| Attack Vector |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| Confidentiality Impact |
|
| Integrity Impact |
|
| Availability Impact |
|
AI Analysis
| AI Description |
A critical stack-based buffer overflow vulnerability in the TOTOLINK X15 router’s formMapReboot function allows remote attackers to potentially execute arbitrary code. This issue is highly severe due to the remote exploitability and the critical nature of the affected device. |
| AI Severity |
Critical |
| Vendor |
TOTOLINK |
| Product |
X15 |
| Affected Version |
1.0.0-B20230714.1105 |
Additional Information
| CVE List |
|
| CWE List |
CWE-121, CWE-119 |
| Bulletin Family |
|
| Source Data |
TOTOLINK X15 1.0.0-B20230714.1105 |
Source Information
| Source Data |
TOTOLINK X15 1.0.0-B20230714.1105 |
| Source Link |
|
Description
A vulnerability, which was classified as critical, was found in TOTOLINK X15 1.0.0-B20230714.1105. This affects the function formMapReboot of the file /boafrm/formMapReboot. The manipulation of the argument deviceMacAddr leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score Summary
View Full CVE Details