Impact
A flaw in the device's web interface allows an attacker to embed arbitrary operating system commands through the passwd1 parameter used by the setSysAdm function. Because the input is not sanitized, a crafted value is executed by the underlying system, granting the attacker control over the device's operating system. The vulnerability falls under the Command Injection family and involves improper input handling. Successful exploitation can read, modify, or delete configuration data and potentially disrupt device operation.
Affected Systems
The vulnerability affects the UTT 进取 521G product line, specifically firmware version 3.1.1-190816. The hardware edition 2.0 is also identified as part of the affected device; no other product lines or firmware revisions are listed as impacted in the available data.
Risk and Exploitability
The CVSS score of 8.6 classifies this issue as high severity. With an EPSS score of 8%, the likelihood of exploitation is considered significant. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, requiring the attacker to access the /goform/setSysAdm endpoint over the network and provide a malicious passwd1 value. If successfully exploited, a single request can lead to full system compromise.
OpenCVE Enrichment