CVE-2025-6824: TOTOLINK X15 HTTP POST Request formParentControl buffer overflow
A vulnerability classified as critical has been found in TOTOLINK X15 up to 1.0.0-B20230714.1105. Affected is an unknown function of the file /boafrm/formParentControl of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6824?
CVE-2025-6824 is classified as critical due to its impact on the TOTOLINK X15's HTTP POST Request Handler leading to a buffer overflow.
How do I fix CVE-2025-6824?
To mitigate CVE-2025-6824, update TOTOLINK X15 firmware to version 1.0.0-B20230715 or later, which addresses the vulnerability.
What systems are affected by CVE-2025-6824?
CVE-2025-6824 affects the TOTOLINK X15 router running firmware version up to 1.0.0-B20230714.1105.
What type of vulnerability is CVE-2025-6824?
CVE-2025-6824 is a buffer overflow vulnerability affecting the HTTP POST Request Handler of the TOTOLINK X15.
Can CVE-2025-6824 be exploited remotely?
Yes, CVE-2025-6824 can be exploited remotely, making it a critical security concern.