CVE-2025-10757
8.8UTT · 1200GW
A buffer overflow vulnerability exists in the UTT 1200GW router via the /goform/formConfigDnsFilterGlobal endpoint, allowing remote authenticated attackers to cause a denial of service.
Executive summary
A buffer overflow vulnerability in the UTT 1200GW router, exploitable by authenticated attackers, presents a significant risk of service disruption.
Vulnerability
This vulnerability is a buffer overflow (CWE-120) triggered by improper input validation of the GroupName parameter within the /goform/formConfigDnsFilterGlobal function. An attacker with valid administrative credentials can send a crafted POST request to this endpoint to corrupt memory and cause a denial of service condition.
Business impact
The successful exploitation of this vulnerability results in a denial of service, which can render the affected router non-functional and disrupt network connectivity for all downstream users. Given the CVSS score of 8.8, this flaw represents a high-severity risk that could lead to significant operational downtime and impact business continuity.
Remediation
Immediate Action: As the vendor has not provided a patch, administrators should restrict access to the administrative management interface to trusted IP addresses only and ensure that default credentials have been changed.
Proactive Monitoring: Monitor device logs for frequent, unexpected reboots or service restarts that may indicate ongoing exploitation attempts.
Compensating Controls: Implement strict firewall rules to prevent unauthorized access to the web management interface of the UTT 1200GW from external or untrusted network segments.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists as documented in the technical write-up provided by the vulnerability researcher.
Analyst recommendation
Due to the lack of an official vendor patch and the availability of a public proof-of-concept, users are advised to treat this device as high-risk. Immediately isolate the management interface from the public internet and restrict access to authorized management workstations to minimize the attack surface until the vendor provides a permanent resolution.
More UTT CVEs
Sources
Originally found and disclosed by cymiao (VulDB User), per the CVE Program record.
- VDB-325112 | UTT 1200GW formConfigDnsFilterGlobal buffer overflow Vulnerability database entry
- VDB-325112 | CTI Indicators (IOB, IOC, IOA)
- Submit #645681 | UTT 进取 1200GW <=v3.0.0-170831 Buffer Overflow Third-party advisory
- Related
- Exploit / PoC