Junglewise Threat Intelligence

CVE-2026-52188: UTT nv518G buffer overflow in gohead component

CVE-2026-52188 · Severity: info · CVSS 7.5 · Published 2026-07-02

Technologies: UTT NV518G. Vendors: UTT.

Executive brief

A buffer overflow vulnerability exists in the UTT nv518G enterprise router. This flaw allows a remote attacker to crash the device's web management service or the entire router by sending a specially crafted web request. This can lead to a total loss of network connectivity and management capabilities for the affected business.

Technical details

A stack-based buffer overflow exists in the 'gohead' web server component of UTT nv518G routers, specifically within the 'sub_497498' function. The vulnerability is caused by a lack of length validation on the 'GroupName' parameter provided in a POST request. An attacker can exploit this by sending an overly long string in the GroupName field, leading to memory corruption. Successful exploitation allows a remote, unauthenticated attacker to cause a denial of service (DoS) by crashing the service. Proof-of-concept code demonstrates the crash using a long string of characters in a standard HTTP POST request to the affected endpoint.

Affected products

  • UTT nv518G firmware nv518GV3v3.2.7-210919-161313

Timeline

  • 2026-07-02: advisory: CVE-2026-52188 published by NVD

References

Related threats