Executive brief
A security vulnerability exists in UTT nv518G enterprise routers that could allow a remote attacker to crash the device. By sending a specially crafted web request, an attacker can trigger a buffer overflow, leading to a denial of service. This can disrupt internet connectivity and business operations for organizations relying on these routers.
Technical details
A stack-based buffer overflow vulnerability exists in the GoAhead web server component of UTT nv518G routers, specifically within the function sub_487330. The vulnerability is caused by a lack of length validation on the 'indexIDNew' parameter provided in a POST request. A remote, unauthenticated attacker can exploit this by sending an excessively long string in the 'indexIDNew' variable, overwriting adjacent memory on the stack. Successful exploitation results in a crash of the web service or the entire device, leading to a denial of service (DoS).
Affected products
- UTT nv518G firmware nv518GV3v3.2.7-210919-161313
Timeline
- 2026-07-02: advisory: CVE-2026-52189 published by NVD