CVE-2025-5790
Last modified
CVE-2025-5790 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A vulnerability classified as critical was found in TOTOLINK X15 1.0.0-B20230714.1105. This vulnerability affects unknown code of the file /boafrm/formIpQoS of the component HTTP POST Request Handler. EPSS estimates a 4.07% chance of exploitation in the next 30 days.
Description
A vulnerability classified as critical was found in TOTOLINK X15 1.0.0-B20230714.1105. This vulnerability affects unknown code of the file /boafrm/formIpQoS of the component HTTP POST Request Handler. The manipulation of the argument mac leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Totolink | X15 Firmware | 1.0.0-b20230714.1105 |
References
- https://github.com/awindog/cve/blob/main/12.mdNot Applicable
- https://vuldb.com/?ctiid.311338Permissions Required
- https://vuldb.com/?id.311338Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.591219Third Party Advisory, VDB Entry
- https://www.totolink.net/Product
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-5790?
How severe is CVE-2025-5790?
How do I fix CVE-2025-5790?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-57894Missing Authorization vulnerability in ollybach WPPizza wppi…4.3
- CVE-2025-57895Cross-Site Request Forgery (CSRF) vulnerability in Hossni Mu…4.3
- CVE-2025-57896Missing Authorization vulnerability in andy_moyle Church Adm…5.3
- CVE-2025-57897Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2025-57898Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-57899Missing Authorization vulnerability in AresIT WP Compress wp…5.3
- CVE-2025-57900Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-57901Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-57902Cross-Site Request Forgery (CSRF) vulnerability in Md Taufiq…6.5
- CVE-2025-57903Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2025-57904Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2025-57905Cross-Site Request Forgery (CSRF) vulnerability in Amin Y Ag…4.3
Are you affected by CVE-2025-5790?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
