Executive brief
A security vulnerability exists in the UTT HiPER 1200GW enterprise router, a device used to manage network traffic and security for businesses. An attacker can exploit this flaw to crash the device or potentially take full control of the router's management interface. This could lead to a complete network outage or allow an attacker to intercept and manipulate corporate data passing through the network.
Technical details
A stack-based buffer overflow vulnerability exists in the UTT HiPER 1200GW router firmware up to version 2.5.3-170306. The flaw is located within the '/goform/setSysAdm' endpoint of the Web Management Interface, specifically due to the unsafe use of the 'strcpy' function when processing the 'sysAdmUser' or 'sysAdmPass' (identified as 'passwd1' in technical proofs) parameters. A remote attacker with low-level authentication can send a specially crafted POST request containing an excessively long string to trigger the overflow. This can result in a denial of service (system crash) or potentially remote code execution. Public exploit code has been released.
Affected products
- UTT HiPER 1200GW up to 2.5.3-170306
Timeline
- 2026-05-27: advisory: NVD publication date