Description
A vulnerability has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects an unknown function of the file /goform/ConfigWirelessBase_5g of the component Web Endpoint. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Published: 2026-07-05
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack-based buffer overflow exists in the UTT HiPER 1250GW web endpoint /goform/ConfigWirelessBase_5g. By manipulating the ssid argument an attacker can overflow the stack and potentially lead to arbitrary code execution on the device. The description does not explicitly state code execution, so this outcome is inferred from the nature of the overflow.

Affected Systems

UTT HiPER 1250GW devices running firmware versions up to and including 3.2.7-210907-180535 are explicitly vulnerable. The CVE specifies "up to 3.2.7-210907-180535" as the affected range; newer releases are not confirmed to contain the vulnerability.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.7, indicating high severity. The EPSS score is below 1 % and the issue is not listed in CISA’s KEV catalog, yet the exploit has been disclosed publicly and can be carried out remotely via the web interface. Consequently, exposed devices face a significant risk of compromise if not mitigated.

Generated by OpenCVE AI on July 26, 2026 at 21:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to any release newer than 3.2.7-210907-180535 to remove the vulnerable code path.
  • If a firmware immediately, block or restrict access to the /goform/ConfigWirelessBase_5g endpoint using firewall or device ACLs so that only trusted management networks can reach it.
  • If the web interface allows it, disable or restrict the SSID configuration option to eliminate the overflow trigger until a patch is available.

Generated by OpenCVE AI on July 26, 2026 at 21:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 05 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects an unknown function of the file /goform/ConfigWirelessBase_5g of the component Web Endpoint. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Title UTT HiPER 1250GW Web Endpoint ConfigWirelessBase_5g stack-based overflow
First Time appeared Utt
Utt hiper 1250gw
Weaknesses CWE-119
CWE-121
CPEs cpe:2.3:a:utt:hiper_1250gw:*:*:*:*:*:*:*:*
Vendors & Products Utt
Utt hiper 1250gw
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Utt Hiper 1250gw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-06T13:39:30.030Z

Reserved: 2026-07-04T07:58:44.620Z

Link: CVE-2026-14721

cve-icon Vulnrichment

Updated: 2026-07-06T13:39:26.476Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T21:30:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow