CVE-2026-76004

9.9

UTT · HiPER 1250GW

The UTT HiPER 1250GW router contains a stack-based buffer overflow in the /goform/aspApBasicConfigUrcp component, reachable via the pvid argument, allowing remote code execution.

Executive summary

The UTT HiPER 1250GW router is susceptible to a critical remote stack-based buffer overflow that could allow an attacker to take control of the device.

Vulnerability

This is a stack-based buffer overflow (CWE-121) occurring in the strcpy function within the HTTP Handler component. An authenticated attacker can manipulate the pvid argument to trigger memory corruption, potentially leading to remote code execution.

Business impact

The compromise of a network router can have catastrophic consequences for an organization, including the potential for man-in-the-middle attacks, traffic redirection, and unauthorized access to internal resources. The CVSS score of 9.9 reflects the critical nature of this vulnerability, as it allows for a complete takeover of network traffic management. The loss of control over core network infrastructure poses a significant threat to operational continuity.

Remediation

Immediate Action: Restrict access to the device management interface to authorized internal networks and monitor for manufacturer firmware updates.

Proactive Monitoring: Inspect network logs for unusual administrative login patterns or traffic anomalies that might suggest exploitation of the management interface.

Compensating Controls: Utilize a firewall to block all traffic to the device's management web interface from untrusted or external network segments.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept is available via GitHub.

Analyst recommendation

Organizations using the UTT HiPER 1250GW must treat this as a high-priority issue. Given the existence of a public proof-of-concept, the likelihood of exploitation is elevated. Immediate steps should be taken to isolate the device management interface from all untrusted networks until a vendor-supplied patch is applied.

More UTT CVEs