Executive brief
The UTT HiPER 1200GW is a network router used in corporate and small-business environments to manage internet connectivity and routing. A remote attacker can trigger a buffer overflow vulnerability by sending a specially crafted web request with an oversized SSID parameter, potentially causing the device to crash, become unavailable, or execute arbitrary code.
Technical details
The vulnerability is a classic buffer overflow in the /goform/formConfigFastDirectionW API endpoint, where unsanitized user input from the "ssid" parameter is copied into a fixed-size buffer using strcpy without bounds checking. The vulnerable code path is triggered when the "wrlessMode" parameter is set to 4, causing the application to copy the ssid value into memory at offset +24 from a pointer without validating string length. The attack requires network access to the router's web management interface and authentication credentials (Digest authentication is shown in the POC); an attacker who gains access to the management interface can supply an arbitrarily long ssid value to overflow the stack or heap. Successful exploitation can lead to denial of service (device crash) or potentially code execution depending on memory layout. Patches for firmware versions beyond 2.5.3-170306 have not been identified in the advisory.
Affected products
- UTT HiPER 1200GW up to 2.5.3-170306
Timeline
- 2026-08-24: disclosed: CVE-2026-78170 published; exploit PoC available on GitHub