Description
UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the timestart parameter of the ConfigAdvideo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published: 2026-04-06
Score: 4.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via buffer overflow
Action: Assess Impact
AI Analysis

Impact

A buffer overflow exists in the timestart parameter of the ConfigAdvideo function of UTT Aggressive HiPER 810G firmware 3v1.7.7-171114. The overflow allows an attacker to send crafted input that can terminate the function, causing the system to become unresponsive. This vulnerability falls under CWE‑120, reflecting a classic stack-based buffer overflow that directly impacts availability.

Affected Systems

The affected system is the UTT Aggressive HiPER 810G hardware running firmware version 3v1.7.7-171114. No other vendors or product versions are listed.

Risk and Exploitability

The CVSS score of 4.5 indicates a moderate risk, and the EPSS score of less than 1% suggests that exploitation of this flaw is currently unlikely to be widely automated. The vulnerability is not recorded in the CISA Known Exploited Vulnerabilities catalog. Based on the description, the likely attack vector involves sending a malicious ConfigAdvideo command—either locally or over a network interface that accepts this function. The exact method of delivery is inferred, as the official advisory does not specify the network or local interface used.

Generated by OpenCVE AI on April 10, 2026 at 19:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check UTT’s official website for a firmware patch that resolves the ConfigAdvideo buffer overflow.
  • If a patch is available, upgrade the device to the latest firmware version that addresses the issue.
  • If no patch exists, consider disabling the ConfigAdvideo functionality through device configuration or restricting network access to the endpoint where the function is exposed.

Generated by OpenCVE AI on April 10, 2026 at 19:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Apr 2026 14:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Buffer Overflow in ConfigAdvideo

Fri, 10 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Utt 810g
Utt 810g Firmware
CPEs cpe:2.3:h:utt:810g:3.0:*:*:*:*:*:*:*
cpe:2.3:o:utt:810g_firmware:*:*:*:*:*:*:*:*
Vendors & Products Utt 810g
Utt 810g Firmware

Wed, 08 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Buffer Overflow in ConfigAdvideo

Tue, 07 Apr 2026 08:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in ConfigAdvideo Function Causes Denial of Service
Weaknesses CWE-119

Tue, 07 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in ConfigAdvideo Function Causes Denial of Service
First Time appeared Utt
Utt hiper 810g
Weaknesses CWE-119
CWE-120
Vendors & Products Utt
Utt hiper 810g
Metrics cvssV3_1

{'score': 4.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
Description UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the timestart parameter of the ConfigAdvideo function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
References

Subscriptions

Utt 810g 810g Firmware Hiper 810g
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-06T19:50:51.659Z

Reserved: 2026-03-09T00:00:00.000Z

Link: CVE-2026-31061

cve-icon Vulnrichment

Updated: 2026-04-06T19:50:47.423Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-06T15:17:08.487

Modified: 2026-04-10T18:21:50.270

Link: CVE-2026-31061

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-13T14:27:53Z

Weaknesses