Executive brief
A security vulnerability exists in the UTT HiPER 2610G router, a device used for enterprise networking and internet connectivity. An attacker can exploit a flaw in the device's web management interface to cause a system crash or potentially take control of the router. This could lead to a total loss of internet availability for the office or unauthorized access to internal network traffic.
Technical details
A stack-based buffer overflow vulnerability exists in the UTT HiPER 2610G router firmware up to version 3.0.0-171107. The flaw is located in the '/goform/formConfigDnsFilterGlobal' endpoint due to the unsafe use of the 'strcpy' function when processing the 'GroupName' parameter. A remote attacker with low-level privileges can provide an overly long string to this parameter to overwrite memory. This can result in a denial-of-service (DoS) or arbitrary code execution. The exploit has been publicly disclosed.
Affected products
- UTT HiPER 2610G up to 3.0.0-171107
Timeline
- 2026-06-08: disclosed: Vulnerability disclosed and assigned CVE-2026-11517
- 2026-06-08: advisory: NVD published the vulnerability details