CVE-2026-1139

8.8

UTT · 进取 520W

A buffer overflow vulnerability in the UTT 进取 520W router allows remote authenticated attackers to cause a denial of service via the /goform/ConfigExceptMSN endpoint.

Executive summary

A buffer overflow vulnerability in UTT 进取 520W routers, triggered via the /goform/ConfigExceptMSN endpoint, poses a significant risk of service disruption.

Vulnerability

The vulnerability exists in the strcpy function within the /goform/ConfigExceptMSN file. An authenticated attacker can trigger a memory corruption event by sending a crafted POST request, leading to a buffer overflow and subsequent denial of service.

Business impact

Successful exploitation of this vulnerability results in a denial of service, effectively taking the router offline. This can disrupt network connectivity for all downstream users and devices relying on the hardware, leading to operational downtime. With a CVSS score of 8.8, the potential for total loss of availability is high, necessitating immediate defensive focus.

Remediation

Immediate Action: Since no official patch is available from the vendor, administrators should restrict access to the web management interface to trusted internal networks only.

Proactive Monitoring: Monitor device logs for repeated crashes or unusual POST requests directed at the /goform/ConfigExceptMSN endpoint.

Compensating Controls: Implement access control lists on the network perimeter to block unauthorized remote access to the administrative management interface.

Exploitation status

Public Exploit Available: Yes, a proof of concept exists, as documented in the researcher write-up linked in the CVE references.

Analyst recommendation

The absence of a vendor-provided patch for this memory corruption flaw elevates the risk to the environment. Security teams must prioritize isolating the management interface from external exposure and applying strict network segmentation to prevent authenticated attackers from leveraging this path to disrupt critical network services.

More UTT CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Published in the daily brief high section
  4. Analyst report written

Sources

Originally found and disclosed by cymiao (VulDB User), per the CVE Program record.