Executive brief
UTT HiPER 1200GW routers are affected by a security vulnerability in their web management interface. An attacker with access to the management console can send specially crafted data to the PPTP client configuration page to crash the device or potentially take full control of it. This could lead to a complete disruption of network services and unauthorized access to the router's internal settings.
Technical details
A stack-based buffer overflow vulnerability exists in the UTT HiPER 1200GW router's web management interface within the /goform/formPptpClientConfig endpoint. The issue stems from improper bounds checking when handling parameters such as the PPTP server address, username, password, or tunnel name, specifically involving an unsafe 'strcpy' operation. An attacker with low-privileged credentials can exploit this by sending a crafted POST request with overly long strings in the affected parameters. Successful exploitation can lead to arbitrary code execution or a denial of service (DoS) condition. Public exploit code has been released.
Affected products
- UTT HiPER 1200GW up to 2.5.3-170306
Timeline
- 2026-05-27: advisory: NVD publication date