Impact
A stack-based buffer overflow exists in the HiPER 1250GW firmware where the strcpy function in /goform/getOneApConfTempEntry is called with an unvalidated tempName argument. By sending a deliberately long value, an attacker can overwrite return addresses on the stack and potentially execute arbitrary code. The weakness is a classic stack corruption scenario (CWE‑119 and CWE‑121) that can compromise confidentiality, integrity, and availability of the device and any network that it controls.
Affected Systems
UTT HiPER 1250GW devices running firmware versions up to v3.2.7-210907-180535 are impacted. The vulnerability is present in the up‑to‑date firmware review report and affects all deployments of the affected software build.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity, and no EPSS score is available, but the vendor acknowledged a publicly available exploit. The attack can be launched remotely against the exposed web interface, and the failure to contain the overflow can lead to remote code execution. The vulnerability is not listed in the CISA KEV catalog, but the publicly known exploit raises the likelihood of real world exploitation.
OpenCVE Enrichment