Impact
A stack-based buffer overflow (CWE-119 and CWE-121) was discovered in the strcpy implementation of the /goform/ConfigAdvideo function in UTT HiPER 1200GW. By supplying a crafted timestart argument the attacker can overflow the stack, potentially gaining arbitrary code execution on the device. This vulnerability directly impacts confidentiality, integrity, and availability, as adversaries could run malicious code or disrupt service.
Affected Systems
The flaw affects UTT HiPER 1200GW firmware versions up to and including v2.5.3-170306. No other versions were enumerated as affected in the provided data.
Risk and Exploitability
The CVSS score of 8.7 classifies the vulnerability as high severity, and the exploit is remotely accessible. EPSS data is not available, and the issue is not yet listed in the CISA KEV catalog, but the public release of an exploit indicates a realistic threat. The likely attack vector is via an unauthenticated HTTP request to the vulnerable endpoint, making the flaw exploitable by any network actor that can reach the device.
OpenCVE Enrichment