Junglewise Threat Intelligence

CVE-2026-9632: UTT HiPER 1250GW stack overflow in formGroupConfig

CVE-2026-9632 · Severity: high · CVSS 8.8 · Published 2026-05-27

Technologies: UTT HiPER 1250GW. Vendors: UTT.

Executive brief

A security vulnerability exists in the UTT HiPER 1250GW enterprise router, a device used to manage network traffic and security for businesses. An attacker can exploit a flaw in the device's web management interface to cause a system crash or potentially take full control of the router. This could lead to a complete disruption of internet services or unauthorized access to the internal corporate network.

Technical details

A stack-based buffer overflow vulnerability exists in the UTT HiPER 1250GW router firmware up to version 3.2.7-210907-180535. The flaw is located in the '/goform/formGroupConfig' endpoint within the Web Management Interface. The root cause is the unsafe use of the 'strcpy' function when processing the 'Profile' (or 'notes') argument, which fails to validate the length of user-supplied input before copying it to a fixed-size stack buffer. An attacker with low-privileged access to the web interface can send a specially crafted POST request with an oversized string to trigger the overflow. This can result in a denial of service (system crash) or potentially remote code execution. A public proof-of-concept exploit has been disclosed.

Affected products

  • UTT HiPER 1250GW up to 3.2.7-210907-180535

Timeline

  • 2026-05-27: disclosed: Vulnerability details and POC published by researcher luozhibo-sec
  • 2026-05-27: advisory: NVD and VulDB published advisory details

References

Related threats