Description
UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the selDateType parameter of the formTaskEdit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published: 2026-04-06
Score: 4.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Update Firmware
AI Analysis

Impact

A buffer overflow exists in the selDateType parameter of the formTaskEdit function within UTT Aggressive HiPER 810G v3 firmware. This flaw allows an attacker to supply specially crafted data that causes the application to crash, leading to a restart of the system and a temporary denial of service. The weakness is a classic CWE‑120 type buffer overflow. The vulnerability is limited to non‑remote execution; the attacker must be able to reach the formTaskEdit entry point, which is typically exposed through the device’s web interface or management protocol. Based on the description, it is inferred that an attacker can trigger the overflow by submitting a request to the editing form with an oversized selDateType field.

Affected Systems

The affected products are UTT Aggressive HiPER 810G devices running firmware version 3.0, specifically the build v1.7.7‑171114. Devices of this model include the 810G series running the 810g firmware. No other provider or version is listed as affected.

Risk and Exploitability

The CVSS score of 4.5 indicates a moderate severity. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild, and the vulnerability is not present in the CISA Known Exploited Vulnerabilities catalog. The attack surface appears to be a web‑based interface that can be accessed over the network, implying remote exploitation is possible if credentials or local access is provided. No publicly available exploit code is reported, and the flaw requires the attacker to control the input to the formTaskEdit function.

Generated by OpenCVE AI on April 10, 2026 at 19:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware upgrade released by UTT that addresses the buffer overflow in the formTaskEdit function.
  • If a firmware update is not yet available, restrict or block external access to the formTaskEdit endpoint by configuring firewalls or web server ACLs, or disable the feature if it is not required.
  • Monitor system and application logs for abnormal termination or repeated restarts that may indicate an attempted overflow attack.
  • Validate input lengths and bounds in any custom or third‑party scripts that interact with the device’s management interface.
  • Review and update the device’s security policy to enforce least privilege and network segmentation.

Generated by OpenCVE AI on April 10, 2026 at 19:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Apr 2026 14:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in selDateType Causes Denial of Service

Fri, 10 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Utt 810g
Utt 810g Firmware
CPEs cpe:2.3:h:utt:810g:3.0:*:*:*:*:*:*:*
cpe:2.3:o:utt:810g_firmware:*:*:*:*:*:*:*:*
Vendors & Products Utt 810g
Utt 810g Firmware

Wed, 08 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in selDateType Causes Denial of Service

Tue, 07 Apr 2026 08:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in selDateType Causing DoS in UTT Aggressive HiPER 810G
Weaknesses CWE-787

Tue, 07 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in selDateType Causing DoS in UTT Aggressive HiPER 810G
First Time appeared Utt
Utt hiper 810g
Weaknesses CWE-120
CWE-787
Vendors & Products Utt
Utt hiper 810g
Metrics cvssV3_1

{'score': 4.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
Description UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the selDateType parameter of the formTaskEdit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
References

Subscriptions

Utt 810g 810g Firmware Hiper 810g
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-04-06T19:54:45.325Z

Reserved: 2026-03-09T00:00:00.000Z

Link: CVE-2026-31066

cve-icon Vulnrichment

Updated: 2026-04-06T19:54:39.866Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-06T15:17:09.200

Modified: 2026-04-10T18:04:02.050

Link: CVE-2026-31066

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-13T14:27:51Z

Weaknesses