Buffer Overflow Vulnerability in TOTOLINK EX1200T Remote Management
CVE-2025-6336
Key Information:
Badges
What is CVE-2025-6336?
A vulnerability affecting the TOTOLINK EX1200T device allows remote attackers to exploit an unspecified function within the HTTP POST Request Handler component. Specifically, manipulating the 'submit-url' argument can trigger a buffer overflow, potentially leading to unauthorized access or denial of service. The problem is rooted in the function located at /boafrm/formTmultiAP and has been publicly disclosed, making it essential for users to apply security measures and updates promptly.
Affected Version(s)
EX1200T 4.1.2cu.5232_B20210713
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved