Impact
A stack-based buffer overflow exists in the UTT HiPER 1250GW web endpoint /goform/ConfigWirelessBase_5g. By manipulating the ssid argument an attacker can overflow the stack and potentially lead to arbitrary code execution on the device. The description does not explicitly state code execution, so this outcome is inferred from the nature of the overflow.
Affected Systems
UTT HiPER 1250GW devices running firmware versions up to and including 3.2.7-210907-180535 are explicitly vulnerable. The CVE specifies "up to 3.2.7-210907-180535" as the affected range; newer releases are not confirmed to contain the vulnerability.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, indicating high severity. The EPSS score is below 1 % and the issue is not listed in CISA’s KEV catalog, yet the exploit has been disclosed publicly and can be carried out remotely via the web interface. Consequently, exposed devices face a significant risk of compromise if not mitigated.
OpenCVE Enrichment