CVE-2025-6150: TOTOLINK X15 HTTP POST Request formMultiAP buffer overflow
A vulnerability classified as critical was found in TOTOLINK X15 1.0.0-B20230714.1105. Affected by this vulnerability is an unknown functionality of the file /boafrm/formMultiAP of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6150?
CVE-2025-6150 is classified as a critical vulnerability.
What type of vulnerability is CVE-2025-6150?
CVE-2025-6150 is a buffer overflow vulnerability in the HTTP POST Request Handler.
How does CVE-2025-6150 affect TOTOLINK X15?
CVE-2025-6150 affects the functionality of the file /boafrm/formMultiAP in TOTOLINK X15.
What is the attack vector for CVE-2025-6150?
The manipulation of the argument submit-url in an HTTP POST request serves as the attack vector for CVE-2025-6150.
How can I mitigate CVE-2025-6150?
To mitigate CVE-2025-6150, update your TOTOLINK X15 device to the latest firmware version provided by the vendor.