Junglewise Threat Intelligence

CVE-2026-11517: UTT HiPER 2610G buffer overflow in formConfigDnsFilterGlobal

CVE-2026-11517 · Severity: high · CVSS 8.8 · Published 2026-06-08

Vendors: UTT.

Executive brief

A security vulnerability exists in the UTT HiPER 2610G router, a device used for enterprise networking and internet connectivity. An attacker can exploit a flaw in the device's web management interface to cause a system crash or potentially take control of the router. This could lead to a total loss of internet availability for the office or unauthorized access to internal network traffic.

Technical details

A stack-based buffer overflow vulnerability exists in the UTT HiPER 2610G router firmware up to version 3.0.0-171107. The flaw is located in the '/goform/formConfigDnsFilterGlobal' endpoint due to the unsafe use of the 'strcpy' function when processing the 'GroupName' parameter. A remote attacker with low-level privileges can provide an overly long string to this parameter to overwrite memory. This can result in a denial-of-service (DoS) or arbitrary code execution. The exploit has been publicly disclosed.

Affected products

  • UTT HiPER 2610G up to 3.0.0-171107

Timeline

  • 2026-06-08: disclosed: Vulnerability disclosed and assigned CVE-2026-11517
  • 2026-06-08: advisory: NVD published the vulnerability details

References

Related threats