Junglewise Threat Intelligence

CVE-2026-18895: UTT HiPER 1250GW stack buffer overflow in APSecurity_5g

CVE-2026-18895 · Severity: high · CVSS 8.8 · Published 2026-08-05

Technologies: UTT HiPER 1250GW. Vendors: UTT.

Executive brief

The UTT HiPER 1250GW is a network router commonly used in small business environments. A vulnerability in its web-based administration interface allows remote attackers to trigger a stack-based buffer overflow by sending a specially crafted request with an oversized "cipher" parameter. This can cause the router to crash or stop functioning, disrupting network connectivity for all users relying on it.

Technical details

A stack-based buffer overflow vulnerability exists in the /goform/APSecurity_5g endpoint due to improper use of strcpy() in the cipher parameter handling. The vulnerable code copies user-supplied input directly to a fixed-size stack buffer without length validation. An unauthenticated remote attacker can exploit this over the network by sending an HTTP POST request with an oversized cipher parameter (as demonstrated in the public proof-of-concept). Successful exploitation can result in denial of service through application crash; remote code execution may be possible depending on stack layout and protections. The vendor was contacted early but did not respond with patches.

Affected products

  • UTT HiPER 1250GW up to 3.2.7-210907-180535

Timeline

  • 2026-08-05: disclosed: Public disclosure via GitHub repository
  • 2026-08-05: other: Exploit code made public in repository

References

Related threats