CVE-2025-6402: TOTOLINK X15 HTTP POST Request formIpv6Setup buffer overflow
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. This vulnerability affects unknown code of the file /boafrm/formIpv6Setup of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6402?
CVE-2025-6402 has been declared as a critical vulnerability.
How do I fix CVE-2025-6402?
To fix CVE-2025-6402, it is recommended to update TOTOLINK X15 to a newer firmware version that addresses this vulnerability.
What component is affected by CVE-2025-6402?
CVE-2025-6402 affects the HTTP POST Request Handler in the file /boafrm/formIpv6Setup.
What type of issue does CVE-2025-6402 exploit?
CVE-2025-6402 exploits a buffer overflow vulnerability through the manipulation of the argument submit-url.
Which version of TOTOLINK X15 is vulnerable to CVE-2025-6402?
TOTOLINK X15 version 1.0.0-B20230714.1105 is vulnerable to CVE-2025-6402.