Junglewise Threat Intelligence

CVE-2026-52192: UTT nv518G command injection in gohead/sub_445C5C

CVE-2026-52192 · Severity: info · CVSS 9.8 · Published 2026-07-02

Technologies: UTT NV518G. Vendors: UTT.

Executive brief

A vulnerability exists in the UTT nv518G enterprise router that allows an attacker to take complete control of the device. By sending a specially crafted network request, a remote attacker can bypass security controls to execute system commands. This could lead to the theft of sensitive data, interception of network traffic, or a total shutdown of the router's services.

Technical details

A command injection vulnerability exists in the UTT nv518G router (firmware version nv518GV3v3.2.7-210919-161313) within the gohead/sub_445C5C component. The root cause is the unsafe use of the sprintf function to construct a system command string using the 'serialNo' parameter without proper sanitization. Specifically, the code executes 'rm -f %s%s.xml' via doSystem(), where the second format string is populated by user-controlled input. An attacker can use shell metacharacters (e.g., ';', '|', or '$()') to break out of the intended command and execute arbitrary code with system privileges. While the initial advisory mentions Denial of Service, the technical analysis confirms full remote code execution (RCE).

Affected products

  • UTT nv518G nv518GV3v3.2.7-210919-161313

Timeline

  • 2026-07-02: disclosed: Initial disclosure via NVD and GitHub report

References

Related threats