Impact
A stack‑based buffer overflow (CWE‑121) exists in the gohead/sub_448384 component of UTT’s nv518G firmware nv518GV3v3.2.7‑210919-161313. When a remote attacker sends crafted data that exceeds the expected buffer size, the overflow corrupts adjacent memory, causing the device to crash. The crash leads to a denial of service; no compromise of confidentiality or data integrity is presented.
Affected Systems
The affected devices are UTT nv518G series units running firmware nv518GV3v3.2.7‑210919-161313. No other vendors or product lines are listed as impacted.
Risk and Exploitability
The CVSS score of 7.5 denotes a high severity vulnerability. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is network‑based; a remote attacker can trigger the overflow by sending malformed packets to the exposed gohead/sub_448384 service, forcing the device to crash and disrupt service.
OpenCVE Enrichment