Executive brief
A security vulnerability exists in the UTT HiPER 1200GW enterprise router, a device used for managing business network traffic and security. An attacker can exploit this flaw to crash the device or potentially take full control of the router's operations. This could lead to a total disruption of internet connectivity for the office or unauthorized access to internal network data.
Technical details
A stack-based buffer overflow vulnerability exists in the UTT HiPER 1200GW router firmware up to version 2.5.3-170306. The flaw is located in the '/goform/formTaskEdit' endpoint, specifically within the handling of the 'selDateType' parameter which is processed using the unsafe 'strcpy' function without proper bounds checking. An attacker with low-privileged network access can send a specially crafted POST request with an oversized string to overwrite the stack. This can result in a denial of service (system crash) or potentially remote code execution. A public exploit (PoC) is available.
Affected products
- UTT HiPER 1200GW up to 2.5.3-170306
Timeline
- 2026-06-01: disclosed
- 2026-06-01: advisory