Impact
A stack‑based buffer overflow was identified in the UTT HiPER 1200GW firmware, triggered by the strcpy function in the /goform/pptpSrvGlobalConfig handler when the EncryptionMode argument is manipulated. The vulnerability allows an attacker to overwrite data on the stack, which can lead to arbitrary code execution. Because the vulnerable code is reachable over the network, the flaw can be exploited remotely without authentication.
Affected Systems
UTT HiPER 1200GW firmware versions up to and including 2.5.3‑170306 are affected. No later releases are listed as vulnerable, and the vendor has not provided a fix that has been confirmed to patch this issue.
Risk and Exploitability
The CVSS score of 8.7 classifies this as a high‑severity vulnerability. An EPSS score is not available, but a publicly disclosed exploit exists and is reported to be usable. The flaw can be triggered via the device’s web interface, meaning an unauthenticated attacker can potentially achieve code execution and compromise the device or the network it serves. The vulnerability is not listed in the CISA KEV catalog, but the high impact and remote nature warrant prompt action.
OpenCVE Enrichment