CVE-2025-5786: TOTOLINK X15 HTTP POST Request formDMZ buffer overflow
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unknown function of the file /boafrm/formDMZ of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5786?
CVE-2025-5786 has been classified as a critical vulnerability.
How do I fix CVE-2025-5786?
To fix CVE-2025-5786, it is recommended to update the TOTOLINK X15 firmware to the latest version provided by the vendor.
What component is affected by CVE-2025-5786?
CVE-2025-5786 affects the HTTP POST Request Handler component in the TOTOLINK X15 router.
What type of vulnerability is CVE-2025-5786?
CVE-2025-5786 is a buffer overflow vulnerability caused by the manipulation of the submit-url argument.
What are the implications of CVE-2025-5786?
Exploitation of CVE-2025-5786 could allow an attacker to execute arbitrary code on the affected system.