CVE-2026-76003
9.9UTT · HiPER 1200GW
The UTT HiPER 1200GW router contains a stack-based buffer overflow vulnerability in the strcpy function, reachable via the timestart argument in /goform/formGroupConfig, allowing remote code execution.
Executive summary
The UTT HiPER 1200GW router is vulnerable to a critical stack-based buffer overflow that enables remote attackers to achieve code execution.
Vulnerability
The vulnerability is a stack-based buffer overflow (CWE-121) caused by unsafe handling of the timestart argument in the /goform/formGroupConfig file. While the CVSS vector indicates that low privileges are required, the remote attack capability makes this a high-risk entry point for unauthorized access.
Business impact
This vulnerability could allow an attacker to gain unauthorized control over network infrastructure, leading to potential traffic interception, internal network reconnaissance, or total denial of service. With a CVSS score of 9.9, the impact on availability, confidentiality, and integrity is severe. Failure to address this flaw could jeopardize the security of the entire network perimeter managed by the device.
Remediation
Immediate Action: Check the vendor website for firmware updates; if no patch exists, restrict access to the device management interface to trusted internal IP addresses only.
Proactive Monitoring: Review device logs for unusual crash patterns or unexpected reboots, which may indicate unsuccessful or successful exploitation attempts.
Compensating Controls: Implement strict network segmentation and ensure the device management interface is not exposed to the public internet.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept is available via GitHub.
Analyst recommendation
Given the availability of a public proof-of-concept and the nature of the vulnerability, the risk of exploitation is high. Administrators should immediately isolate the affected hardware from external networks and apply available firmware updates as soon as they are released by the vendor.