Executive brief
A security vulnerability exists in UTT nv518G enterprise routers. An attacker can send a specially crafted web request to the device to manipulate its internal database. This can lead to full control over the router, potentially allowing the attacker to intercept network traffic, disrupt internet connectivity, or access sensitive configuration data.
Technical details
A SQL injection vulnerability exists in the UTT nv518G router firmware version nv518GV3v3.2.7-210919-161313. The vulnerability is located in the 'gohead/sub_463bbc' component, specifically within the handling of the 'delsn' POST parameter. The application uses 'strtok_r' to process the input and subsequently passes the unsanitized data into a 'sprintf' function to construct a SQL query. A remote, unauthenticated attacker can exploit this by sending a crafted 'delsn' value (e.g., using boolean-based injection or stacked queries) to manipulate database logic or achieve remote code execution.
Affected products
- UTT nv518G nv518GV3v3.2.7-210919-161313
Timeline
- 2026-07-01: disclosed: CVE published to NVD dataset