CVE Details
Basic Information
| Title | TOTOLINK X15 HTTP POST Request formMapDelDevice buffer overflow |
|---|---|
| Type | cve |
| Published | 2025-07-27T22:02:07.627Z |
| Modified | 2025-07-27T22:02:07.627Z |
Product Information
| Vendor | TOTOLINK |
|---|---|
| Product | X15 |
| Version | 1.0.0-B20230714.1105 |
CVSS Information
| Base Score | 8.7 (HIGH) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P |
AI Analysis
| AI Description | A buffer overflow vulnerability in the TOTOLINK X15 router’s HTTP POST request handler allows remote attackers to execute arbitrary code via the macstr argument in formMapDelDevice. This critical vulnerability can be exploited without authentication, leading to potential system compromise. |
|---|---|
| AI Severity | High |
| AI Vendor | TOTOLINK |
| AI Product | TOTOLINK X15 |
| AI Version | 1.0.0-B20230714.1105 |
Affected Products
- TOTOLINK X15 1.0.0-B20230714.1105
Additional Information
| CWE List | CWE-120, CWE-119 |
|---|---|
| Source | VulDB |
Description
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unknown function of the file /boafrm/formMapDelDevice of the component HTTP POST Request Handler. The manipulation of the argument macstr leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.