CVE-2025-8246: TOTOLINK X15 HTTP POST Request formRoute buffer overflow
Published Jul 27, 2025
·Updated
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical. Affected by this issue is some unknown functionality of the file /boafrm/formRoute of the component HTTP POST Request Handler. The manipulation of the argument submit-url leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
3 affected components
TOTOLINK X15
All of the following
TOTOLINK X15 Firmware=1.0.0-b20230714.1105
TOTOLINK X15
Event History
Jul 27, 2025
CVE Published
via MITRE·11:02 PM
Data Sourced
via MITRE·11:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 19, 58473
Event
via NVD·08:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-8246?
CVE-2025-8246 has been rated as critical.
2
How do I fix CVE-2025-8246?
To fix CVE-2025-8246, update your TOTOLINK X15 to the latest firmware version provided by TOTOLINK.
3
What component is affected by CVE-2025-8246?
CVE-2025-8246 affects the HTTP POST Request Handler in the TOTOLINK X15.
4
What type of vulnerability is CVE-2025-8246?
CVE-2025-8246 is a buffer overflow vulnerability.
5
What functional area does CVE-2025-8246 impact?
CVE-2025-8246 impacts the submit-url argument within the /boafrm/formRoute functionality.