CVE-2025-14572

8.8

UTT · 进取 512W

A memory corruption vulnerability exists in the UTT 进取 512W router via the hidcontact argument in the /goform/formWebAuthGlobalConfig endpoint.

Executive summary

A critical memory corruption vulnerability in the UTT 进取 512W router allows for remote exploitation, posing a significant risk to device integrity.

Vulnerability

This vulnerability involves memory corruption triggered by manipulating the hidcontact argument within the /goform/formWebAuthGlobalConfig file. The vulnerability is remotely exploitable by an authenticated user.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting a High severity rating due to the potential for total loss of system integrity and availability. Successful exploitation could lead to unauthorized code execution, resulting in full system compromise, loss of administrative control, and potential lateral movement within the network.

Remediation

Immediate Action: As the vendor has not provided a patch, users should restrict network access to the management interface of the affected device and disable the web authentication configuration feature if not strictly required.

Proactive Monitoring: Monitor device logs for unusual activity related to the /goform/formWebAuthGlobalConfig endpoint and watch for signs of system instability or unexpected reboots that may indicate memory corruption attempts.

Compensating Controls: Implement strict firewall rules to ensure that only authorized administrative IP addresses can access the management interface of the UTT 进取 512W device.

Exploitation status

Public Exploit Available: Yes, a published proof of concept exists via the GitHub issue referenced in the vulnerability disclosure.

Analyst recommendation

Given the lack of vendor response and the availability of a public proof of concept, this vulnerability poses an elevated risk. Administrators should immediately isolate the affected hardware from untrusted networks and monitor for unauthorized access attempts. Replacing the legacy device is recommended if the vendor continues to fail to provide security updates.

More UTT CVEs

Sources

Originally found and disclosed by alc9700 (VulDB User), per the CVE Program record.