📦 X15 Firmware

by Totolink

🔍 What is X15 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-8245

HIGH CVSS 8.8 Jul 27, 2025

This critical buffer overflow vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formMultiAPVLAN end...

CVE-2025-8243

HIGH CVSS 8.8 Jul 27, 2025

This critical buffer overflow vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formMapDel endpoint...

CVE-2025-6402

HIGH CVSS 8.8 Jun 21, 2025

This critical buffer overflow vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formIpv6Setup endpo...

CVE-2025-6399

HIGH CVSS 8.8 Jun 21, 2025

A critical buffer overflow vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formIPv6Addr endpoint....

CVE-2025-5789

HIGH CVSS 8.8 Jun 6, 2025

This critical vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code via a buffer overflow in the HTTP POST request handler. Attackers can exploit this without authent...

CVE-2025-5788

HIGH CVSS 8.8 Jun 6, 2025

This critical vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code via a buffer overflow in the HTTP POST request handler. Attackers can exploit this by sending spec...

CVE-2025-5786

HIGH CVSS 8.8 Jun 6, 2025

A critical buffer overflow vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formDMZ endpoint. This...

CVE-2025-5785

HIGH CVSS 8.8 Jun 6, 2025

This critical buffer overflow vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formWirelessTbl end...

CVE-2025-5738

HIGH CVSS 8.8 Jun 6, 2025

A critical buffer overflow vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formStats endpoint. Th...

CVE-2025-5736

HIGH CVSS 8.8 Jun 6, 2025

A critical buffer overflow vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formNtp endpoint. This...

CVE-2025-5734

HIGH CVSS 8.8 Jun 6, 2025

A critical buffer overflow vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST requests to the /boafrm/formWlanRedirect endpo...

CVE-2025-5503

HIGH CVSS 8.8 Jun 3, 2025

This critical vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the formMapReboot function. Attackers can exploit this withou...

CVE-2025-5502

MEDIUM CVSS 6.3 Jun 3, 2025

This critical vulnerability in TOTOLINK X15 routers allows remote attackers to execute arbitrary commands via command injection in the formMapReboot function. Attackers can exploit this by manipulatin...