CVE-2025-5907
Published: 10 June 2025
Summary
CVE-2025-5907 is a high-severity Improper Restriction of Operations within the Bounds of a Memory Buffer (CWE-119) vulnerability in Totolink Ex1200T Firmware. Its CVSS base score is 7.4 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked in the top 19.0% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
Deeper analysis
A critical buffer overflow vulnerability exists in the TOTOLINK EX1200T wireless router up to firmware version 4.1.2cu.5232_B20210713. The issue is located in unknown code of the file /boafrm/formFilter within the HTTP POST Request Handler component and stems from improper input validation that triggers memory corruption, classified under CWE-119 and CWE-120. The flaw carries a CVSS 4.0 score of 7.4 and can be reached over the network.
An authenticated remote attacker can exploit the weakness by submitting a crafted HTTP POST request to the affected endpoint, achieving high-impact outcomes that include full control over device memory, arbitrary code execution, or disruption of router services. The exploit has already been published publicly, enabling straightforward reproduction by threat actors with valid credentials.
No vendor patch or mitigation guidance is detailed in the available references, which include a public exploit description on GitHub, multiple VulDB entries, and the TOTOLINK product site. The associated EPSS remains low and essentially flat at 0.0142–0.0143, indicating limited observed exploitation interest to date.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-17614
Vulnerability details
A vulnerability classified as critical was found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713. This vulnerability affects unknown code of the file /boafrm/formFilter of the component HTTP POST Request Handler. The manipulation leads to buffer overflow. The attack can be initiated…
more
remotely. The exploit has been disclosed to the public and may be used.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Remote buffer overflow in public-facing HTTP POST handler (/boafrm/formFilter) enables exploitation of public-facing application for initial access (T1190) and application/system exploitation for endpoint denial of service (T1499.004), impacting CIA triad.
Affected Assets
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Managed runtimes used by platform-independent applications (e.g., JVM, CLR) enforce memory safety, preventing most buffer overflows that require direct memory manipulation.
Ongoing control assessments and code testing (static/dynamic analysis, fuzzing) surface memory buffer restriction failures, which are then remediated before release.
Memory protections (e.g., W^X, ASLR) make exploitation of buffer-boundary violations far harder to turn into code execution.
Detects exploitation attempts that produce memory corruption, crashes, or anomalous behavior.