Impact
A SQL Injection flaw (CWE-89) occurs in the gohead/sub_463bbc component of the UTT nv518G firmware. The vulnerability allows a remote attacker to insert arbitrary SQL statements that the system will execute, giving the attacker the ability to run arbitrary code on the device. This could compromise the confidentiality, integrity, and availability of the firmware and any data stored on the device.
Affected Systems
The affected device is the UTT nv518G firmware version nv518GV3v3.2.7-210919-161313. No additional vendor or product variants are identified in the advisory.
Risk and Exploitability
The CVSS score of 9.8 indicates a high severity impact. The EPSS score is below 1%, suggesting a low probability of exploitation at the moment. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, and although authentication requirements are not explicitly stated, the lack of mention implies the flaw may be exploitable without prior access. Exploitability remains low due to the low EPSS, but the high severity makes it a critical risk for affected devices.
OpenCVE Enrichment