Description
A vulnerability was detected in UTT HiPER 810 1.7.4-141218. The impacted element is the function sub_43F020 of the file /goform/formPdbUpConfig. Performing a manipulation of the argument policyNames results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Problem types
Product status
Timeline
| 2026-02-06: | Advisory disclosed |
| 2026-02-06: | VulDB entry created |
| 2026-02-14: | VulDB entry last update |
Credits
cha0yang (VulDB User)
References
vuldb.com/?id.344770 (VDB-344770 | UTT HiPER 810 formPdbUpConfig sub_43F020 command injection)
vuldb.com/?ctiid.344770 (VDB-344770 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.747222 (Submit #747222 | UTT (艾泰) HiPER 810 nv810v4v1.7.4-141218 Command Injection)
github.com/cha0yang1/UTT810CVE/blob/main/CVEreadme2.md