Executive brief
A security vulnerability exists in the UTT nv518G enterprise router. An attacker can send a specially crafted web request to the device to cause it to crash or become unresponsive. This results in a denial of service, disrupting internet connectivity and network operations for the business.
Technical details
A stack-based buffer overflow exists in the UTT nv518G router within the 'gohead/sub_447CAC' component. The vulnerability is triggered when the application handles 'oldName' and 'newName' parameters via the '/formLinkageConfReName' endpoint. The software uses 'strcat' to append user-controlled strings to a fixed-size stack buffer that already contains a long USB path string. If the 'oldName' or 'newName' parameters exceed approximately 40 bytes, the buffer overflows, corrupting adjacent stack memory and the return address. A remote, unauthenticated attacker can exploit this to cause a denial of service (DoS) by crashing the device.
Affected products
- UTT nv518G nv518GV3v3.2.7-210919-161313
Timeline
- 2026-06-30: advisory: CVE published by NVD/MITRE