CVE-2025-5738: TOTOLINK X15 HTTP POST Request formStats buffer overflow
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical. Affected by this issue is some unknown functionality of the file /boafrm/formStats of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5738?
CVE-2025-5738 has been rated as critical due to its potential to cause significant harm.
How do I fix CVE-2025-5738?
To fix CVE-2025-5738, update the TOTOLINK X15 firmware to the latest version provided by the manufacturer.
What systems are affected by CVE-2025-5738?
CVE-2025-5738 affects the TOTOLINK X15 router running firmware version 1.0.0-B20230714.1105.
What type of vulnerability is CVE-2025-5738?
CVE-2025-5738 is a buffer overflow vulnerability related to the HTTP POST request handler.
What can attackers do with CVE-2025-5738?
Attackers exploiting CVE-2025-5738 could potentially execute arbitrary code on the affected device.