CVE-2026-8137

8.8

Totolink · X5000R

A buffer overflow vulnerability in Totolink X5000R allows attackers to execute arbitrary code via the submit-url parameter.

Executive summary

A critical buffer overflow vulnerability in the Totolink X5000R router allows remote attackers to achieve arbitrary code execution or denial of service.

Vulnerability

This vulnerability is a memory corruption flaw caused by a stack-based buffer overflow in the sub_458E40 function of the /boafrm/formDdns endpoint, triggered by an unauthenticated attacker supplying an oversized submit-url parameter.

Business impact

A successful exploit of this flaw allows attackers to completely compromise the affected router, resulting in full loss of device control, persistent internal network access, and potential interception of network traffic. Given the CVSS score of 8.8, this vulnerability poses a severe risk to organizational perimeter security and operational continuity by enabling malicious actors to establish a pivot point into the local network.

Remediation

Immediate Action: Isolate the affected router from the network or disable external management access until a vendor-supplied firmware update addressing the vulnerability is applied.

Proactive Monitoring: Monitor network traffic for anomalous administrative requests targeting the /boafrm/formDdns endpoint and check device logs for unexpected reboots indicative of service crashes.

Compensating Controls: Implement firewall rules to restrict access to the router management interface exclusively to trusted internal administrative subnets.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exploit is available via GitHub issue reports and referenced write-ups.

Analyst recommendation

Administrators must treat this vulnerability with high urgency due to the availability of public exploit code and the potential for complete device takeover. Apply vendor patches as soon as they become available, and enforce strict network segmentation to limit exposure of router management services.

More Totolink CVEs

Sources

Originally found and disclosed by kiciot (VulDB User), per the CVE Program record.