Impact
A stack‑based buffer overflow exists in the strcpy call within the APSecurity_5g module of UTT HiPER 1250GW. By manipulating the cipher argument, an attacker can overwrite the stack and execute arbitrary code. This flaw corresponds to CWE‑119 and CWE‑121 and allows remote exploitation without local interaction.
Affected Systems
The affected product is UTT HiPER 1250GW versions up to 3.2.7‑210907‑180535. All devices running these revisions are vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score is 8.7, indicating high severity. EPSS data is not available, so an exact exploitation probability cannot be determined, but the vulnerability is publicly known and a public exploit exists. The vulnerability is not listed in CISA KEV, but the lack of a vendor response increases risk. The attack vector is remote, requiring only the ability to send a crafted cipher value to the /goform/APSecurity_5g endpoint.
OpenCVE Enrichment