Executive brief
The UTT HiPER 1200GW is a network router used to manage and route corporate or small office traffic. A stack buffer overflow vulnerability in its web administration interface allows an attacker to send a specially crafted request to the /goform/ConfigAdvideo endpoint, potentially crashing the device or executing arbitrary code. This could result in loss of network connectivity, data interception, or complete device compromise.
Technical details
The vulnerability is a stack-based buffer overflow in the ConfigAdvideo web form handler, specifically within the strcpy() function used to process the "timestart" parameter. The vulnerable code lacks proper boundary checking when copying user-supplied input into a fixed-size stack buffer. An attacker can send a POST request to /goform/ConfigAdvideo with an oversized "timestart" parameter to trigger the overflow. Authentication may be required depending on device configuration. Successful exploitation allows denial of service or remote code execution with device privileges.
Affected products
- UTT HiPER 1200GW up to v2.5.3-170306
Timeline
- 2026-08-05: disclosed
- other: Exploit released to public