PatchSiren

UTT CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH UTT CVE published 2026-08-19

CVE-2026-76003

A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306, specifically in the strcpy function of /goform/formGroupConfig. This stack-based buffer overflow vulnerability can be exploited remotely by manipulating the timestart argument, potentially leading to significant impact. Organizations should review their deployments and consider patching or mitigation strategies. The CVE record indicate [truncated]

HIGH UTT CVE published 2026-08-09

CVE-2026-19341

CVE-2026-19341 is a stack-based buffer overflow vulnerability in UTT HiPER 1200GW up to 2.5.3-170306. The vulnerability is caused by improper handling of the EncryptionMode argument in the strcpy function of /goform/pptpSrvGlobalConfig. This allows for remote exploitation, potentially leading to code execution or denial of service. Organizations should be aware of this vulnerability and take necessary act [truncated]

HIGH UTT CVE published 2026-08-05

CVE-2026-18898

A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306, which affects the function strcpy of the file /goform/ConfigAdvideo, leading to a stack-based buffer overflow. The manipulation of the argument timestart results in this vulnerability. The attack can be launched remotely, and the exploit has been released to the public. Organizations should be aware of this vulnerability and take [truncated]

HIGH UTT CVE published 2026-08-05

CVE-2026-18897

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T02:16:37.773Z and has not been modified since then. The vulnerability affects UTT HiPER 1250GW up to v3.2.7-210907-180535, specifically the strcpy function in /goform/getOneApConfTempEntry, leading to a stack-based buffer overflow. The attack can be initiated remotely, and a public exploit is ava [truncated]

HIGH UTT CVE published 2026-08-05

CVE-2026-18895

CVE-2026-18895 is a stack-based buffer overflow vulnerability in the UTT HiPER 1250GW device, specifically in the strcpy function of /goform/APSecurity_5g. The vulnerability allows for remote exploitation and has a CVSS score of 7.4. The exploit has been made public. Affected product deployments should be reviewed for potential exposure, and network administrators should prioritize patching and monitoring [truncated]

HIGH UTT CVE published 2026-06-08

CVE-2026-11517

CVE-2026-11517 is a high-severity buffer overflow vulnerability in UTT HiPER 2610G up to 3.0.0-171107. The vulnerability affects the strcpy function in /goform/formConfigDnsFilterGlobal, allowing for remote exploitation through manipulation of the GroupName argument. The vulnerability has a CVSS score of 7.4 and is considered HIGH severity. The CVE was published on 2026-06-08T15:16:43.233Z and last modifi [truncated]

LOW UTT CVE published 2026-06-08

CVE-2026-11516

CVE-2026-11516 is a buffer overflow vulnerability in UTT HiPER 2610G up to 3.0.0-171107. The vulnerability affects the strcpy function in /goform/formNatStaticMap, which can be exploited by manipulating the NatBinds argument. The vulnerability has a CVSS score of 2 and is considered LOW severity. The exploit has been made public and could be used.

HIGH UTT CVE published 2026-05-27

CVE-2026-9632

A stack-based buffer overflow vulnerability exists in the UTT HiPER 1250GW router firmware through version 3.2.7-210907-180535. The vulnerability resides in the `strcpy` function within the `/goform/formGroupConfig` endpoint of the Web Management Interface. An attacker with low privileges can remotely trigger the overflow by manipulating the `Profile` argument, potentially achieving high impact on confide [truncated]

HIGH UTT CVE published 2026-05-27

CVE-2026-9631

A stack-based buffer overflow vulnerability exists in UTT HiPER 1250GW devices running firmware up to version 3.2.7-210907-180535. The vulnerability resides in the `strcpy` function within the `/goform/formConfigFastDirectionW` endpoint of the web management interface. An attacker can exploit this by manipulating the `Profile` argument, leading to remote code execution. The CVSS 4.0 score of 7.4 (HIGH) re [truncated]

HIGH UTT CVE published 2026-05-27

CVE-2026-9628

A stack-based buffer overflow vulnerability exists in the UTT HiPER 1200GW router firmware through version 2.5.3-170306. The vulnerability resides in the `/goform/formPptpClientConfig` endpoint of the Web Management Interface, where multiple PPTP configuration parameters—including server address, username, password, and tunnel name—are susceptible to improper bounds checking. Successful exploitation could [truncated]