Impact
A buffer overflow exists in the strcpy implementation within the /goform/formFireWall component of the HiPER 810G management interface. Manipulation of the GroupName argument can overflow the destination buffer, potentially allowing remote code execution or privilege escalation. The weakness is categorized as CWE‑119 and CWE‑120, indicating uncontrolled memory access due to improper bounds checking.
Affected Systems
The vulnerability affects UTT’s HiPER 810G hardware running firmware versions up to 1.7.7‑171114. Users deploying any firmware in that range are at risk. No subsequent versions are listed in the current data.
Risk and Exploitability
The CVSS base score of 8.7 classifies the flaw as high severity, while the EPSS score of less than 1% indicates low current exploitation probability. However, the exploit is public and can be launched remotely, and the vulnerability is not yet listed in CISA’s KEV catalog. Attackers can target any externally reachable device that exposes the management interface, making the risk significant if the interface is left exposed.
OpenCVE Enrichment