Junglewise Threat Intelligence

CVE-2026-52190: UTT nv518G buffer overflow in gohead/sub_448384

CVE-2026-52190 · Severity: info · CVSS 7.5 · Published 2026-07-01

Technologies: UTT NV518G. Vendors: UTT.

Executive brief

A buffer overflow vulnerability exists in UTT nv518G enterprise routers. This flaw allows a remote attacker to crash the device's web management service or the entire system by sending a specially crafted network request. This results in a denial of service, disrupting network connectivity and administrative access for the organization.

Technical details

A stack-based buffer overflow vulnerability exists in the UTT nv518G router (firmware version nv518GV3v3.2.7-210919-161313) within the 'gohead/sub_448384' component. The vulnerability is rooted in the 'websRedirectUrcp' function, which retrieves a user-controlled parameter via 'websGetVar' and subsequently processes it using 'sprintf' into a fixed-size buffer (v6) without adequate bounds checking. An attacker can exploit this by sending a POST request with an oversized 'isGroupOpt' parameter. Successful exploitation leads to a crash of the GoAhead process, resulting in a denial of service (DoS). No authentication appears to be required for this network-reachable endpoint.

Affected products

  • UTT nv518G nv518GV3v3.2.7-210919-161313

Timeline

  • 2026-07-01: disclosed: Initial publication of CVE-2026-52190

References

Related threats