Junglewise Threat Intelligence

CVE-2026-14721: UTT HiPER 1250GW stack overflow in ConfigWirelessBase_5g

CVE-2026-14721 · Severity: high · CVSS 8.8 · Published 2026-07-05

Technologies: UTT HiPER 1250GW. Vendors: UTT.

Executive brief

The UTT HiPER 1250GW router, a device used for enterprise networking, contains a security flaw in its web management interface. An attacker with access to the management console can send a specially crafted request to the wireless configuration settings to crash the device or potentially take full control of it. This could lead to a complete disruption of network services or unauthorized access to internal network traffic.

Technical details

A stack-based buffer overflow exists in the UTT HiPER 1250GW router firmware up to version 3.2.7-210907-180535. The vulnerability is located within the Web Endpoint component, specifically in the '/goform/ConfigWirelessBase_5g' file. The root cause is the unsafe use of the 'strcpy' function when processing the 'ssid' (or 'Profile') parameter without adequate boundary checks. A remote attacker with low-level authentication can exploit this by sending a POST request with an oversized SSID string, leading to memory corruption. This can result in a denial of service (system crash) or potentially arbitrary code execution. A public exploit (PoC) has been disclosed.

Affected products

  • UTT HiPER 1250GW up to 3.2.7-210907-180535

Timeline

  • 2026-07-05: disclosed: Vulnerability disclosed to vendor and public via GitHub/VulDB
  • 2026-07-05: advisory: CVE-2026-14721 published

References

Related threats