TOTOLINK X15 Stack-Based Buffer Overflow Vulnerability in formMapReboot Function

Vulnerability

A critical stack-based buffer overflow vulnerability has been identified in the TOTOLINK X15 router, specifically in version 1.0.0-B20230714.1105. The issue arises in the formMapReboot function within the file /boafrm/formMapReboot, where improper handling of the deviceMacAddr argument allows for remote exploitation. This vulnerability has been publicly disclosed, and the vendor was notified but did not respond.

Impact

Exploitation of this vulnerability leads to a stack-based buffer overflow, which can commonly result in arbitrary code execution or causing the device to crash.

Reproduction

The vulnerability can be reproduced by sending a crafted request to the formMapReboot function, including a maliciously formatted deviceMacAddr argument. This will trigger the stack-based buffer overflow by overwriting the return address on the stack.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.6
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.