A vulnerability classified as critical was found in TOTOLINK X15 1.0.0-B20230714.1105. This vulnerability affects unknown code of the file /boafrm/formIpQoS of the component HTTP POST Request Handler. The manipulation of the argument mac leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Jun 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Totolink
Totolink x15 Totolink x15 Firmware |
|
CPEs | cpe:2.3:h:totolink:x15:-:*:*:*:*:*:*:* cpe:2.3:o:totolink:x15_firmware:1.0.0-b20230714.1105:*:*:*:*:*:*:* |
|
Vendors & Products |
Totolink
Totolink x15 Totolink x15 Firmware |
Fri, 06 Jun 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability classified as critical was found in TOTOLINK X15 1.0.0-B20230714.1105. This vulnerability affects unknown code of the file /boafrm/formIpQoS of the component HTTP POST Request Handler. The manipulation of the argument mac leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
Title | TOTOLINK X15 HTTP POST Request formIpQoS buffer overflow | |
Weaknesses | CWE-119 CWE-120 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-06-06T17:31:11.039Z
Updated: 2025-06-06T17:31:11.039Z
Reserved: 2025-06-06T07:17:50.053Z
Link: CVE-2025-5790

No data.

Status : Analyzed
Published: 2025-06-06T18:15:35.840
Modified: 2025-06-09T19:08:31.530
Link: CVE-2025-5790

No data.