Impact
A buffer overflow exists in the gohead/sub_483ba0 component of UTT nv518G firmware nv518GV3v3.2.7‑210919‑161313. When a remote attacker supplies specially crafted data to this component, memory corruption occurs which can cause the router to crash, resulting in a denial of service. The entry explicitly states the outcome is a denial of service and makes no mention of code execution, data theft, or privilege escalation, so the primary security consequence is service disruption. The flaw is a classic stack‑based overflow (CWE‑120).
Affected Systems
UTT nv518G routers that are running firmware version nv518GV3v3.2.7‑210919‑161313. No other UTT device models or firmware revisions are documented in the CVE record, and the vendor has not released a patch or workaround yet.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation in the current threat landscape. The vulnerability is reachable over the network; local access is not required. The situation is not listed in the CISA KEV catalog, implying no known widespread exploitation. An attacker who can reach the affected interface may trigger the overflow remotely, leading to a denial‑of‑service event; however, the probability of such an attack occurring is low as currently indicated.
OpenCVE Enrichment