Executive brief
A buffer overflow vulnerability exists in UTT nv518G enterprise routers. This flaw allows a remote attacker to crash the device's web management service or the entire router by sending a specially crafted network request. This results in a denial of service, disrupting network connectivity and administrative access for the organization.
Technical details
A stack-based buffer overflow exists in the 'gohead/sub_472f08' component of UTT nv518G routers. The vulnerability is located in the handling of the 'delstr' POST parameter, which is processed using strtok_r() and sscanf() to extract MAC addresses. The function uses strncpy() to write data into a 1500-byte stack buffer (v24) within a loop. While there is a loop bound check (n4 < 1462), it is insufficient because each iteration advances the write pointer by 38 bytes. After approximately 40 iterations, the writes exceed the buffer's bounds, overwriting adjacent stack variables and the return address, leading to a crash or potential remote code execution.
Affected products
- UTT nv518G nv518GV3 v3.2.7-210919-161313
Timeline
- 2026-06-30: disclosed: Initial disclosure via GitHub and CVE assignment