CVE-2025-5736: TOTOLINK X15 HTTP POST Request formNtp buffer overflow
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unknown function of the file /boafrm/formNtp of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5736?
CVE-2025-5736 has been classified as a critical vulnerability.
How do I fix CVE-2025-5736?
To fix CVE-2025-5736, it is recommended to update the TOTOLINK X15 to the latest firmware version that addresses this vulnerability.
What component is affected by CVE-2025-5736?
CVE-2025-5736 affects the HTTP POST Request Handler of the TOTOLINK X15 router.
What is the exploit method for CVE-2025-5736?
CVE-2025-5736 can be exploited through manipulation of the argument submit-url, which leads to a buffer overflow.
What devices are impacted by CVE-2025-5736?
CVE-2025-5736 impacts the TOTOLINK X15 router running firmware version 1.0.0-B20230714.1105.