Home

Description

A vulnerability was determined in UTT 进取 521G 3.1.1-190816. The impacted element is the function sub_446B18 of the file /goform/formPdbUpConfig. Executing a manipulation of the argument policyNames can lead to os command injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED Reserved 2026-02-07 | Published 2026-02-08 | Updated 2026-02-23 | Assigner VulDB




HIGH: 8.6CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
HIGH: 7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
HIGH: 7.2CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
8.3AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR

Problem types

OS Command Injection

Command Injection

Product status

3.1.1-190816
affected

Timeline

2026-02-07:Advisory disclosed
2026-02-07:VulDB entry created
2026-02-09:VulDB entry last update

Credits

cha0yang (VulDB User) reporter

References

vuldb.com/?id.344891 (VDB-344891 | UTT 进取 521G formPdbUpConfig sub_446B18 os command injection) vdb-entry technical-description

vuldb.com/?ctiid.344891 (VDB-344891 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required

vuldb.com/?submit.749733 (Submit #749733 | UTT (艾泰) UTT521G NV521Gv2v3.1.1-190816 Command Injection) third-party-advisory

github.com/cha0yang1/UTT521G/blob/main/RCE2.md exploit

cve.org (CVE-2026-2188)

nvd.nist.gov (CVE-2026-2188)

Download JSON