Junglewise Threat Intelligence

CVE-2026-9631: UTT HiPER 1250GW stack overflow in Web Management Interface

CVE-2026-9631 · Severity: high · CVSS 8.8 · Published 2026-05-27

Technologies: UTT HiPER 1250GW. Vendors: UTT.

Executive brief

UTT HiPER 1250GW enterprise routers are affected by a security flaw in their web management interface. An attacker with access to the management console can send a specially crafted request to crash the device or potentially take full control of the router. This could lead to a complete disruption of network services and unauthorized access to internal network traffic.

Technical details

A stack-based buffer overflow vulnerability exists in the UTT HiPER 1250GW router's web management interface. The flaw is located in the /goform/formConfigFastDirectionW endpoint, where the application uses the unsafe 'strcpy' function to process the 'Profile' (or 'ssid') argument without proper bounds checking. An authenticated remote attacker can exploit this by sending a POST request with an oversized string, leading to memory corruption. Successful exploitation can result in a Denial of Service (DoS) or arbitrary code execution. A public exploit (PoC) is available, and the vulnerability affects firmware versions up to 3.2.7-210907-180535.

Affected products

  • UTT HiPER 1250GW up to 3.2.7-210907-180535

Timeline

  • 2026-05-27: advisory: NVD publication date

References

Related threats