CVE-2025-10757

8.8

UTT · 1200GW

A buffer overflow vulnerability exists in the UTT 1200GW router via the /goform/formConfigDnsFilterGlobal endpoint, allowing remote authenticated attackers to cause a denial of service.

Executive summary

A buffer overflow vulnerability in the UTT 1200GW router, exploitable by authenticated attackers, presents a significant risk of service disruption.

Vulnerability

This vulnerability is a buffer overflow (CWE-120) triggered by improper input validation of the GroupName parameter within the /goform/formConfigDnsFilterGlobal function. An attacker with valid administrative credentials can send a crafted POST request to this endpoint to corrupt memory and cause a denial of service condition.

Business impact

The successful exploitation of this vulnerability results in a denial of service, which can render the affected router non-functional and disrupt network connectivity for all downstream users. Given the CVSS score of 8.8, this flaw represents a high-severity risk that could lead to significant operational downtime and impact business continuity.

Remediation

Immediate Action: As the vendor has not provided a patch, administrators should restrict access to the administrative management interface to trusted IP addresses only and ensure that default credentials have been changed.

Proactive Monitoring: Monitor device logs for frequent, unexpected reboots or service restarts that may indicate ongoing exploitation attempts.

Compensating Controls: Implement strict firewall rules to prevent unauthorized access to the web management interface of the UTT 1200GW from external or untrusted network segments.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists as documented in the technical write-up provided by the vulnerability researcher.

Analyst recommendation

Due to the lack of an official vendor patch and the availability of a public proof-of-concept, users are advised to treat this device as high-risk. Immediately isolate the management interface from the public internet and restrict access to authorized management workstations to minimize the attack surface until the vendor provides a permanent resolution.

More UTT CVEs

Sources

Originally found and disclosed by cymiao (VulDB User), per the CVE Program record.