CVE-2026-7419

8.8

UTT · HiPER 1250GW

The UTT HiPER 1250GW router contains a buffer overflow vulnerability in the formTaskEdit_ap function, allowing remote attackers to cause a denial of service.

Executive summary

A buffer overflow vulnerability in the UTT HiPER 1250GW router, reachable via the Profile parameter, poses a significant risk of service disruption.

Vulnerability

This is a buffer overflow vulnerability (CWE-120) triggered by the unsafe use of the strcpy function within the route/goform/formTaskEdit_ap endpoint. While the CVSS vector indicates that low privileges are required, the vulnerability is reachable over the network by an authenticated user.

Business impact

Successful exploitation of this vulnerability can lead to a complete denial of service for the affected router, which may disrupt critical network connectivity for the organization. Given the CVSS score of 8.8, this flaw represents a high risk to availability and operational continuity. Unauthorized manipulation of router configurations could also potentially lead to broader network security degradation.

Remediation

Immediate Action: Update the UTT HiPER 1250GW firmware to a version beyond 3.2.7-210907-180535 as soon as an official patch is released by the vendor.

Proactive Monitoring: Monitor device logs for anomalous traffic directed at the /goform/formTaskEdit_ap endpoint and watch for unexpected system reboots or service instability.

Compensating Controls: Restrict access to the router administrative interface to trusted management subnets only and employ a Web Application Firewall (WAF) or equivalent network inspection tool to filter malicious POST requests targeting the identified endpoint.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept is available via the technical research write-up referenced in the CVE record.

Analyst recommendation

Due to the high severity of this memory corruption flaw and the availability of a public proof-of-concept, immediate attention is required. Administrators should verify their firmware versions and restrict administrative access to the device until a permanent vendor-supplied fix is applied. Prioritize the isolation of these devices from public-facing networks to minimize exposure.

More UTT CVEs

Sources

Originally found and disclosed by maple_s (VulDB User), per the CVE Program record.