CVE-2025-5515: TOTOLINK X2000R formMapDel command injection
A vulnerability, which was classified as critical, has been found in TOTOLINK X2000R 1.0.0-B20230726.1108. Affected by this issue is some unknown functionality of the file /boafrm/formMapDel. The manipulation of the argument devicemac1 leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5515?
CVE-2025-5515 is classified as a critical vulnerability.
What software is affected by CVE-2025-5515?
CVE-2025-5515 affects the TOTOLINK X2000R firmware version 1.0.0-B20230726.1108.
What type of vulnerability is CVE-2025-5515?
CVE-2025-5515 is a command injection vulnerability affecting the argument devicemac1.
How do I fix CVE-2025-5515?
To fix CVE-2025-5515, update your TOTOLINK X2000R device to the latest firmware version provided by the manufacturer.
What are the potential impacts of CVE-2025-5515?
The exploitation of CVE-2025-5515 can lead to unauthorized command execution on the affected device.