Description
Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_487330 component
Published: 2026-07-02
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The UTT nv518G firmware revision v3.2.7‑210919‑161313 contains a buffer overflow flaw (CWE‑120) in the gohead/sub_487330 component. A crafted request can overwrite memory, corrupt execution flow, and trigger a crash. The flaw permits a remote attacker to cause a denial of service by making the device reboot or become unresponsive, but it does not provide a path to remote code execution or compromise confidentiality.

Affected Systems

Affected systems are devices running the UTT nv518G firmware revision v3.2.7‑210919‑161313. Any UTT 518G units that are still operating with this firmware version are potentially impacted until updated.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity vulnerability. The EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not in the CISA KEV catalog. However, a remote attacker can send a specially crafted payload to trigger the overflow over the vulnerable interface, resulting in a service interruption. Immediate remediation is advised to prevent potential denial of service incidents.

Generated by OpenCVE AI on July 21, 2026 at 12:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to the latest version that includes the defensive fix for the gohead buffer overflow.
  • Restrict network exposure by placing the device in a trusted segment or applying firewall rules to block traffic to the vulnerable interface.
  • Monitor device logs and performance for unexpected restarts or crashes that may indicate exploitation attempts.
  • If possible, disable or isolate the gohead functionality as a temporary workaround while awaiting an official patch.

Generated by OpenCVE AI on July 21, 2026 at 12:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Leads to Denial of Service

Fri, 17 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Leading to Remote Denial of Service

Tue, 14 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Leading to Remote Denial of Service

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Causes Denial of Service

Sun, 12 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Causes Denial of Service

Sat, 11 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow Leading to Denial of Service in UTT nv518G Firmware

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow Leading to Denial of Service in UTT nv518G Firmware

Thu, 09 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Causes Remote Denial of Service

Tue, 07 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Causes Remote Denial of Service

Tue, 07 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Buffer Overflow in UTT nv518G Firmware

Mon, 06 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Buffer Overflow in UTT nv518G Firmware

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow Leading to Denial of Service in UTT nv518G Firmware
Weaknesses CWE-120

Mon, 06 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Buffer Overflow Leading to Denial of Service in UTT nv518G Firmware
Weaknesses CWE-120

Sun, 05 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Causes Remote Denial of Service
Weaknesses CWE-120

Sun, 05 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Causes Remote Denial of Service
Weaknesses CWE-120

Sat, 04 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Causing Denial of Service
Weaknesses CWE-120

Fri, 03 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Causing Denial of Service
Weaknesses CWE-120

Fri, 03 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Buffer Overflow in UTT nv518G Firmware
Weaknesses CWE-119
CWE-122

Fri, 03 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Buffer Overflow in UTT nv518G Firmware
Weaknesses CWE-119
CWE-122

Thu, 02 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Utt
Utt nv518g
Vendors & Products Utt
Utt nv518g

Thu, 02 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_487330 component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-06T14:49:36.028Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-52189

cve-icon Vulnrichment

Updated: 2026-07-06T14:49:27.089Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:45:02Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')