Description
A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected is the function strcpy of the file /goform/setSysAdm. Such manipulation of the argument GroupName leads to buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Problem types
Product status
Timeline
| 2026-03-20: | Advisory disclosed |
| 2026-03-20: | VulDB entry created |
| 2026-03-20: | VulDB entry last update |
Credits
kunlun (VulDB User)
References
vuldb.com/?id.352011 (VDB-352011 | UTT HiPER 1250GW setSysAdm strcpy buffer overflow)
vuldb.com/?ctiid.352011 (VDB-352011 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.773565 (Submit #773565 | UTT HiPER 1250GW <=v3.2.7-210907-180535 Buffer Overflow)
github.com/hmKunlun/UTTHiPER/blob/main/HiPER 1250GW.md