Home

Description

A security vulnerability has been detected in UTT HiPER 520 1.7.7-160105. This impacts the function sub_44D264 of the file /goform/formPdbUpConfig of the component Web Management Interface. The manipulation of the argument policyNames leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED Reserved 2026-02-20 | Published 2026-02-20 | Updated 2026-02-24 | Assigner VulDB




HIGH: 8.6CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
HIGH: 7.2CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
HIGH: 7.2CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
8.3AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR

Problem types

OS Command Injection

Command Injection

Product status

1.7.7-160105
affected

Timeline

2026-02-20:Advisory disclosed
2026-02-20:VulDB entry created
2026-02-20:VulDB entry last update

Credits

Ruler-Chovy (VulDB User) reporter

References

vuldb.com/?id.347082 (VDB-347082 | UTT HiPER 520 Web Management formPdbUpConfig sub_44D264 os command injection) vdb-entry technical-description

vuldb.com/?ctiid.347082 (VDB-347082 | CTI Indicators (IOB, IOC, TTP, IOA)) signature permissions-required

vuldb.com/?submit.753964 (Submit #753964 | UTT HiPER 520 nv520v3v1.7.7-160105 Command Injection) third-party-advisory

github.com/cha0yang1/UTT520CVE/blob/main/UTTRCE1.md exploit

cve.org (CVE-2026-2846)

nvd.nist.gov (CVE-2026-2846)

Download JSON