Junglewise Threat Intelligence

CVE-2026-11516: UTT HiPER 2610G buffer overflow in formNatStaticMap

CVE-2026-11516 · Severity: medium · CVSS 5.5 · Published 2026-06-08

Vendors: UTT.

Executive brief

A security vulnerability exists in the UTT HiPER 2610G enterprise router. An attacker with access to the local network could exploit this flaw to cause a system crash or potentially gain unauthorized control over the device. This could lead to network downtime or unauthorized access to internal traffic managed by the router.

Technical details

A stack-based buffer overflow vulnerability exists in the UTT HiPER 2610G router up to version 3.0.0-171107. The issue is located in the 'strcpy' function within the '/goform/formNatStaticMap' component. By manipulating the 'NatBinds' argument, an attacker with low privileges and adjacent network access can trigger the overflow. This can result in a denial of service (system crash) or potentially remote code execution. Public exploit code has been reported for this vulnerability.

Affected products

  • UTT HiPER 2610G up to 3.0.0-171107

Timeline

  • 2026-06-08: disclosed
  • 2026-06-08: advisory

References

Related threats