Executive brief
A security vulnerability exists in the UTT HiPER 2610G enterprise router. An attacker with access to the local network could exploit this flaw to cause a system crash or potentially gain unauthorized control over the device. This could lead to network downtime or unauthorized access to internal traffic managed by the router.
Technical details
A stack-based buffer overflow vulnerability exists in the UTT HiPER 2610G router up to version 3.0.0-171107. The issue is located in the 'strcpy' function within the '/goform/formNatStaticMap' component. By manipulating the 'NatBinds' argument, an attacker with low privileges and adjacent network access can trigger the overflow. This can result in a denial of service (system crash) or potentially remote code execution. Public exploit code has been reported for this vulnerability.
Affected products
- UTT HiPER 2610G up to 3.0.0-171107
Timeline
- 2026-06-08: disclosed
- 2026-06-08: advisory