Description
SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to execute arbitrary code via the gohead/sub_463bbc component
Published: 2026-07-01
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A SQL Injection flaw (CWE-89) occurs in the gohead/sub_463bbc component of the UTT nv518G firmware. The vulnerability allows a remote attacker to insert arbitrary SQL statements that the system will execute, giving the attacker the ability to run arbitrary code on the device. This could compromise the confidentiality, integrity, and availability of the firmware and any data stored on the device.

Affected Systems

The affected device is the UTT nv518G firmware version nv518GV3v3.2.7-210919-161313. No additional vendor or product variants are identified in the advisory.

Risk and Exploitability

The CVSS score of 9.8 indicates a high severity impact. The EPSS score is below 1%, suggesting a low probability of exploitation at the moment. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, and although authentication requirements are not explicitly stated, the lack of mention implies the flaw may be exploitable without prior access. Exploitability remains low due to the low EPSS, but the high severity makes it a critical risk for affected devices.

Generated by OpenCVE AI on July 21, 2026 at 15:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an updated firmware version for the UTT nv518G device that resolves the SQL Injection flaw.
  • Restrict or disable the gohead/sub_463bbc interface by limiting access to it if the functionality is unnecessary.
  • Configure input validation or deploy a Web Application Firewall rule set to detect and block suspicious SQL statements targeting the vulnerable component.
  • Monitor system and database logs for anomalous queries and coordinate incident response procedures in case of suspicious activity.

Generated by OpenCVE AI on July 21, 2026 at 15:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title SQL Injection in UTT nv518G Firmware Component Enabling Remote Code Execution

Wed, 15 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title SQL Injection in UTT nv518G Firmware Component Enabling Remote Code Execution

Tue, 14 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via SQL Injection in UTT nv518G Firmware

Mon, 13 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via SQL Injection in UTT nv518G Firmware

Sun, 12 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title SQL Injection in UTT nv518G Firmware Enables Remote Code Execution

Sat, 11 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title SQL Injection in UTT nv518G Firmware Enables Remote Code Execution

Fri, 10 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title SQL Injection Vulnerability in UTT nv518G Firmware Allows Remote Code Execution

Thu, 09 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title SQL Injection Vulnerability in UTT nv518G Firmware Allows Remote Code Execution

Wed, 08 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via SQL Injection in UTT nv518G Firmware

Tue, 07 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via SQL Injection in UTT nv518G Firmware

Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title SQL Injection Exploit in UTT nv518G Firmware Through gohead/sub_463bbc Component

Mon, 06 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title SQL Injection Exploit in UTT nv518G Firmware Through gohead/sub_463bbc Component

Sun, 05 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via SQL Injection in UTT nv518G Firmware

Sun, 05 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via SQL Injection in UTT nv518G Firmware

Sat, 04 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title SQL Injection in UTT nv518G gohead/sub_463bbc Component

Sat, 04 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title SQL Injection in UTT nv518G gohead/sub_463bbc Component

Fri, 03 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title SQL Injection in UTT nv518G Firmware Enables Remote Code Execution

Fri, 03 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title SQL Injection in UTT nv518G Firmware Enables Remote Code Execution

Fri, 03 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via SQL Injection in UTT nv518G Firmware

Thu, 02 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via SQL Injection in UTT nv518G Firmware

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Remote SQL Injection Exploitation in UTT nv518G Leading to Arbitrary Code Execution
Weaknesses CWE-89

Thu, 02 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Remote SQL Injection Exploitation in UTT nv518G Leading to Arbitrary Code Execution
Weaknesses CWE-89

Thu, 02 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Utt
Utt nv518g
Vendors & Products Utt
Utt nv518g

Wed, 01 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Description SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to execute arbitrary code via the gohead/sub_463bbc component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-02T13:05:11.119Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-52186

cve-icon Vulnrichment

Updated: 2026-07-02T13:05:07.160Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T15:15:08Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')