Junglewise Threat Intelligence

CVE-2026-52193: UTT nv518G buffer overflow in gohead component

CVE-2026-52193 · Severity: info · CVSS 7.5 · Published 2026-06-30

Technologies: UTT NV518G. Vendors: UTT.

Executive brief

A security vulnerability exists in the UTT nv518G enterprise router. An attacker can send a specially crafted web request to the device to cause it to crash or become unresponsive. This results in a denial of service, disrupting internet connectivity and network operations for the business.

Technical details

A stack-based buffer overflow exists in the UTT nv518G router within the 'gohead/sub_447CAC' component. The vulnerability is triggered when the application handles 'oldName' and 'newName' parameters via the '/formLinkageConfReName' endpoint. The software uses 'strcat' to append user-controlled strings to a fixed-size stack buffer that already contains a long USB path string. If the 'oldName' or 'newName' parameters exceed approximately 40 bytes, the buffer overflows, corrupting adjacent stack memory and the return address. A remote, unauthenticated attacker can exploit this to cause a denial of service (DoS) by crashing the device.

Affected products

  • UTT nv518G nv518GV3v3.2.7-210919-161313

Timeline

  • 2026-06-30: advisory: CVE published by NVD/MITRE

References

Related threats