← Terug naar overzicht

A stack-based buffer overflow vulnerability has been identified in UTT HiPER 1250GW devices running firmware up to version 3.2.7-210907-180535. The vulnerability resides in the strcpy function within the /goform/aspRemoteApConfTempSend endpoint of the HTTP Request Handler component. An attacker can exploit this by manipulating the 'Profile' argument to trigger a stack-based buffer overflow. The attack can be performed remotely without requiring physical access to the device. A public exploit is already available, increasing the risk of active exploitation in the wild. The vulnerability is classified as high severity given its remote exploitability and public exploit availability. Network administrators using affected UTT HiPER 1250GW devices should apply patches or mitigations immediately.

Affected products

  • UTT HiPER 1250GW up to 3.2.7-210907-180535

Related CVE's

  • CVE-2026-78169

Categories

  • Mobile & IoT
  • Network Infrastructure