CVE-2025-8242: TOTOLINK X15 HTTP POST Request formFilter buffer overflow
A vulnerability has been found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This vulnerability affects unknown code of the file /boafrm/formFilter of the component HTTP POST Request Handler. The manipulation of the argument ip6addr/url/vpnPassword/vpnUser leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8242?
CVE-2025-8242 is classified as a critical vulnerability.
How do I fix CVE-2025-8242?
To fix CVE-2025-8242, update TOTOLINK X15 to the latest software version that addresses this vulnerability.
What components are affected by CVE-2025-8242?
CVE-2025-8242 affects the HTTP POST Request Handler in the TOTOLINK X15 device.
What inputs are involved in CVE-2025-8242?
CVE-2025-8242 is triggered by manipulating the ip6addr, url, vpnPassword, or vpnUser arguments.
Is CVE-2025-8242 a local or remote vulnerability?
CVE-2025-8242 is a remote vulnerability that can be exploited without physical access to the device.