Impact
The UTT nv518G firmware revision v3.2.7‑210919‑161313 contains a buffer overflow flaw (CWE‑120) in the gohead/sub_487330 component. A crafted request can overwrite memory, corrupt execution flow, and trigger a crash. The flaw permits a remote attacker to cause a denial of service by making the device reboot or become unresponsive, but it does not provide a path to remote code execution or compromise confidentiality.
Affected Systems
Affected systems are devices running the UTT nv518G firmware revision v3.2.7‑210919‑161313. Any UTT 518G units that are still operating with this firmware version are potentially impacted until updated.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability. The EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not in the CISA KEV catalog. However, a remote attacker can send a specially crafted payload to trigger the overflow over the vulnerable interface, resulting in a service interruption. Immediate remediation is advised to prevent potential denial of service incidents.
OpenCVE Enrichment