CVE-2025-6144: TOTOLINK EX1200T HTTP POST Request formSysCmd buffer overflow
A vulnerability has been found in TOTOLINK EX1200T 4.1.2cu.5232B20210713 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formSysCmd of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6144?
CVE-2025-6144 is classified as a critical vulnerability.
How do I fix CVE-2025-6144?
To mitigate CVE-2025-6144, it is recommended to update the TOTOLINK EX1200T firmware to the latest version.
What component is affected by CVE-2025-6144?
CVE-2025-6144 affects the HTTP POST Request Handler of the file /boafrm/formSysCmd.
What is the impact of CVE-2025-6144?
The manipulation of the argument submit-url in CVE-2025-6144 can lead to potential unauthorized access.
Is my device vulnerable to CVE-2025-6144?
If you are using the TOTOLINK EX1200T with firmware version 4.1.2cu.5232_B20210713, your device is vulnerable to CVE-2025-6144.