Executive brief
A buffer overflow vulnerability exists in the UTT nv518G enterprise router. This flaw allows a remote attacker to crash the device's web management service by sending a specially crafted web request. An exploit would result in a denial of service, preventing administrators from managing the network and potentially disrupting network traffic.
Technical details
A stack-based buffer overflow vulnerability exists in the GoAhead web server component of the UTT nv518G router, specifically within the function sub_416f28. The vulnerability is caused by the unsafe use of the 'strcpy' function when processing the 'GroupName' parameter from a POST request. The application fails to validate the length of the user-supplied string before copying it into a fixed-size buffer (InstPointByIndex + 180). A remote, unauthenticated attacker can exploit this by sending an oversized GroupName value, leading to a memory corruption that crashes the service (Denial of Service).
Affected products
- UTT nv518G nv518GV3v3.2.7-210919-161313
Timeline
- 2026-06-30: disclosed: Initial disclosure and CVE assignment