HIGH🇵🇱 Wersja polska

CVE-2026-2071

CVSS 7.4v4.0pub. 2026-02-07upd. 2026-02-13

A vulnerability was found in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formP2PLimitConfig. Performing a manipulation of the argument except results in buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Utt 520w

    HW
    Utt
    3.0
  • Utt 520w Firmware

    OS
    Utt
    1.7.7-180627
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2026-31059CRITICAL9.8PL ✓same product

RCE w UTT HiPER 520W — wykonanie dowolnych poleceń przez /goform/formDia

CVE-2026-2070HIGH7.4same product

A vulnerability has been found in UTT 进取 520W 1.7.7-180627. The affected element is the function strcpy of the...

CVE-2026-2066HIGH7.4same product

A weakness has been identified in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /gofo...

CVE-2026-2067HIGH7.4same product

A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. This vulnerability affects the functio...

CVE-2026-2068HIGH7.4same product

A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /...