Impact
The flaw is a classic buffer overflow caused by the use of an unsafe strcpy function in the /goform/ConfigExceptAli interface of the UTT HiPER 810G firmware. The copying operation can overwrite adjacent memory, potentially corrupting internal data structures. The CVE description does not assert arbitrary code execution; however, such overflows can lead to undefined behavior, including possible crashes, data loss, or other forms of memory corruption that could impact device availability and the integrity of its configuration.
Affected Systems
The vulnerability is documented for UTT HiPER 810G firmware version 1.7.7‑171114. No other firmware versions are listed as affected in the available information.
Risk and Exploitability
The CVSS score of 8.7 signals a high severity risk. The EPSS score is less than 1%, indicating a very low probability of exploitation at present. The issue is not included in CISA's KEV catalog. The description states that the attack can be launched remotely, likely through the device's web management interface at /goform/ConfigExceptAli. An attacker would need network connectivity to the device, and the vulnerability may be exploitable with or without authentication, depending on the interface’s protection mechanisms.
OpenCVE Enrichment