Executive brief
UTT HiPER 1250GW enterprise routers are affected by a security flaw in their web management interface. An attacker with access to the management console can send a specially crafted request to crash the device or potentially take full control of the router. This could lead to a complete disruption of network services and unauthorized access to internal network traffic.
Technical details
A stack-based buffer overflow vulnerability exists in the UTT HiPER 1250GW router's web management interface. The flaw is located in the /goform/formConfigFastDirectionW endpoint, where the application uses the unsafe 'strcpy' function to process the 'Profile' (or 'ssid') argument without proper bounds checking. An authenticated remote attacker can exploit this by sending a POST request with an oversized string, leading to memory corruption. Successful exploitation can result in a Denial of Service (DoS) or arbitrary code execution. A public exploit (PoC) is available, and the vulnerability affects firmware versions up to 3.2.7-210907-180535.
Affected products
- UTT HiPER 1250GW up to 3.2.7-210907-180535
Timeline
- 2026-05-27: advisory: NVD publication date