Description
UTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the timeRangeName parameter of the formConfigDnsFilterGlobal function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published: 2026-04-06
Score: 4.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Assess Impact
AI Analysis

Impact

A buffer overflow exists in the timeRangeName field processed by the formConfigDnsFilterGlobal function of UTT Aggressive HiPER 1200GW. The overflow can be triggered by a character string that exceeds the allocated buffer size, allowing an attacker to send a malicious input that corrupts memory and eventually causes the device to crash or become unreachable. The vulnerability leads to loss of availability but does not directly expose confidential data or alter device configuration. The weakness is identified as a classic uncontrolled buffer overrun.

Affected Systems

The flaw affects UTT Aggressive HiPER 1200GW firmware versions up to and including 2.5.3-170306. No newer firmware versions are listed in the source, so devices running that revision or earlier should be considered vulnerable. The product is sold by UTT and appears in the Common Platform Enumeration as an industrial networking device.

Risk and Exploitability

The CVSS score of 4.5 indicates a moderate impact, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, which further reduces the likelihood of widespread active attacks. Nonetheless, the attack vector is inferred to require remote access to the device’s configuration interface, as the buffer overflow is triggered by a crafted input supplied through the timeRangeName parameter. If an attacker can remotely provide this input, they could disrupt service for any user depending on the device.

Generated by OpenCVE AI on April 10, 2026 at 19:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether the device firmware is at or above 2.5.3-170306 and, if not, update to the latest firmware release that removes the vulnerability.
  • If an immediate firmware update is not feasible, restrict the size of the timeRangeName field by configuring input validation or by applying a local firewall rule that limits the length of incoming configuration packets.
  • Continuously monitor device logs for abnormal restart events or repeated failures associated with configuration updates to detect attempted exploitation early.

Generated by OpenCVE AI on April 10, 2026 at 19:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Apr 2026 14:30:00 +0000

Type Values Removed Values Added
Title TimeRangeName Buffer Overflow Causes Denial of Service in UTT Aggressive HiPER 1200GW

Fri, 10 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Utt 1200gw
Utt 1200gw Firmware
CPEs cpe:2.3:h:utt:1200gw:-:*:*:*:*:*:*:*
cpe:2.3:o:utt:1200gw_firmware:*:*:*:*:*:*:*:*
Vendors & Products Utt 1200gw
Utt 1200gw Firmware

Wed, 08 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Title TimeRangeName Buffer Overflow Causes Denial of Service in UTT Aggressive HiPER 1200GW

Tue, 07 Apr 2026 08:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in timeRangeName Parameter Leading to Denial of Service in UTT Aggressive HiPER 1200GW v2.5.3-170306
Weaknesses CWE-119
CWE-121

Tue, 07 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in timeRangeName Parameter Leading to Denial of Service in UTT Aggressive HiPER 1200GW v2.5.3-170306
First Time appeared Utt
Utt hiper 1200gw
Weaknesses CWE-119
CWE-120
CWE-121
Vendors & Products Utt
Utt hiper 1200gw
Metrics cvssV3_1

{'score': 4.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
Description UTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the timeRangeName parameter of the formConfigDnsFilterGlobal function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
References

Subscriptions

Utt 1200gw 1200gw Firmware Hiper 1200gw
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-06T19:44:56.292Z

Reserved: 2026-03-09T00:00:00.000Z

Link: CVE-2026-31058

cve-icon Vulnrichment

Updated: 2026-04-06T19:44:42.439Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-06T15:17:08.090

Modified: 2026-04-10T18:22:46.667

Link: CVE-2026-31058

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-13T14:27:55Z

Weaknesses