Executive brief
A vulnerability exists in UTT nv518G enterprise routers, which are used to manage business network traffic and connectivity. An attacker can remotely send specially crafted commands to the device to take complete control of the router. This could lead to the theft of sensitive data passing through the network, a total shutdown of internet services, or a foothold for further attacks within the corporate network.
Technical details
A command injection vulnerability exists in the UTT nv518G router (firmware version nv518GV3v3.2.7-210919-161313) within the 'gohead/sub_44af70' component. The issue stems from a lack of input sanitization on parameters such as 'staticGateway' passed to the 'doSystem()' function. By injecting shell metacharacters (e.g., ';', '|', or '$()') into a POST request, a remote, unauthenticated attacker can execute arbitrary system commands with root privileges. This allows for full device compromise, including data interception and persistent access. While the NVD entry initially categorized this as Denial of Service, the technical proof-of-concept confirms arbitrary command execution.
Affected products
- UTT nv518G nv518GV3v3.2.7-210919-161313
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory