Executive brief
A security vulnerability exists in the UTT nv518G enterprise router. An attacker can send a specially crafted web request to the device to cause it to crash or potentially take full control of the system. This could lead to a total disruption of network services or unauthorized access to corporate data passing through the router.
Technical details
A stack-based buffer overflow exists in the UTT nv518G router (firmware version nv518GV3v3.2.7-210919-161313) within the GoAhead web server component. The vulnerability is located in function sub_444C8C, where the 'port' parameter from an HTTP POST request is retrieved via websGetVar(). This user-controlled string is then appended to a fixed-size 104-byte stack buffer using strcat() without any length validation. An attacker providing a 'port' value exceeding approximately 72 bytes can overwrite the saved return address on the stack, leading to a denial of service (DoS) or remote code execution (RCE). No authentication is required to exploit this vulnerability over the network.
Affected products
- UTT nv518G nv518GV3v3.2.7-210919-161313
Timeline
- 2026-07-02: disclosed: Initial disclosure via NVD and GitHub report