Junglewise Threat Intelligence

CVE-2026-78169: UTT HiPER 1250GW stack buffer overflow in HTTP request handler

CVE-2026-78169 · Severity: critical · CVSS 9.9 · Published 2026-08-24

Technologies: UTT HiPER 1250GW. Vendors: UTT.

Executive brief

The UTT HiPER 1250GW router is a network appliance used to manage corporate and small-office internet connectivity. A stack buffer overflow vulnerability in the remote AP configuration endpoint allows attackers with network access to send specially crafted requests that crash the device, causing a denial of service. This can disrupt internet connectivity for all users depending on the router.

Technical details

A stack buffer overflow vulnerability exists in the HTTP request handler component at the /goform/aspRemoteApConfTempSend endpoint. The vulnerable function uses strcpy() without bounds checking to copy user-supplied input from the "Profile" (or similar "remoteSrcTemp") parameter into a fixed-size buffer. An attacker with network access to the device can send an oversized string to overflow the stack, overwriting the return address or other sensitive data. This allows remote code execution or denial of service. The vulnerability affects UTT HiPER 1250GW firmware version 3.2.7-210907-180535 and earlier; patch availability has not been confirmed.

Affected products

  • UTT HiPER 1250GW up to 3.2.7-210907-180535

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: advisory

References

Related threats