CVE-2025-6399: TOTOLINK X15 HTTP POST Request formIPv6Addr buffer overflow
A vulnerability, which was classified as critical, was found in TOTOLINK X15 1.0.0-B20230714.1105. Affected is an unknown function of the file /boafrm/formIPv6Addr of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6399?
CVE-2025-6399 is classified as a critical vulnerability.
How do I fix CVE-2025-6399?
To fix CVE-2025-6399, apply the latest firmware update for the TOTOLINK X15 device.
What component is affected by CVE-2025-6399?
CVE-2025-6399 affects the HTTP POST Request Handler of the TOTOLINK X15.
What kind of vulnerability is CVE-2025-6399?
CVE-2025-6399 is a buffer overflow vulnerability that can be exploited through the argument submit-url.
Which product versions are impacted by CVE-2025-6399?
CVE-2025-6399 impacts TOTOLINK X15 version 1.0.0-B20230714.1105.