Executive brief
A buffer overflow vulnerability exists in the UTT nv518G enterprise router. This flaw allows a remote attacker to send a specially crafted web request that crashes the device's management interface or the device itself. This results in a denial of service, preventing legitimate users from accessing the network or managing the router.
Technical details
A stack-based buffer overflow exists in the UTT nv518G router firmware (version nv518GV3v3.2.7-210919-161313) within the GoAhead web server component, specifically in the 'sub_483ba0' function. The vulnerability is caused by a lack of length validation on the 'indexIDNew' parameter passed via a POST request. A remote, unauthenticated attacker can exploit this by sending an oversized string in the 'indexIDNew' variable, leading to memory corruption and a denial of service (DoS) condition. A proof-of-concept (PoC) has been publicly disclosed.
Affected products
- UTT nv518G nv518GV3v3.2.7-210919-161313
Timeline
- 2026-07-02: disclosed: Initial disclosure and CVE assignment