Executive brief
A buffer overflow vulnerability exists in the UTT nv518G enterprise router. This flaw allows a remote attacker to crash the device's web management service or the entire router by sending a specially crafted network request. An exploit could lead to a total loss of network connectivity and management capabilities for the affected business environment.
Technical details
A heap-based buffer overflow exists in the UTT nv518G router within the GoAhead web server component, specifically in function sub_425994. The vulnerability is caused by an unsafe strcpy operation where the 'Binds' parameter from a POST request is copied into a heap structure without a length check. A remote, unauthenticated attacker can exploit this by sending a long string in the 'Binds' parameter, leading to memory corruption and a denial of service (DoS). The issue was identified in firmware version nv518GV3v3.2.7-210919-161313.
Affected products
- UTT nv518G nv518GV3v3.2.7-210919-161313
Timeline
- 2026-06-30: advisory: CVE-2026-52198 published by NVD/MITRE