Description
Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_448384 component
Published: 2026-07-01
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack‑based buffer overflow (CWE‑121) exists in the gohead/sub_448384 component of UTT’s nv518G firmware nv518GV3v3.2.7‑210919-161313. When a remote attacker sends crafted data that exceeds the expected buffer size, the overflow corrupts adjacent memory, causing the device to crash. The crash leads to a denial of service; no compromise of confidentiality or data integrity is presented.

Affected Systems

The affected devices are UTT nv518G series units running firmware nv518GV3v3.2.7‑210919-161313. No other vendors or product lines are listed as impacted.

Risk and Exploitability

The CVSS score of 7.5 denotes a high severity vulnerability. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is network‑based; a remote attacker can trigger the overflow by sending malformed packets to the exposed gohead/sub_448384 service, forcing the device to crash and disrupt service.

Generated by OpenCVE AI on July 21, 2026 at 15:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Identify all UTT nv518G units running firmware nv518GV3v3.2.7‑210919-161313.
  • Check the vendor website or the provided download link for an updated firmware that addresses the buffer overflow.
  • If no update is available or cannot be applied promptly, disable or restrict the vulnerable gohead/sub_448384 service, enable any built‑in stack‑overflow protection mechanisms (such as stack canaries or address space layout randomization if available), and configure the device to reject packets that exceed expected size limits.
  • Monitor device logs and network traffic for abnormal crashes or repeated denial‑of‑service incidents.

Generated by OpenCVE AI on July 21, 2026 at 15:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow Causing Denial of Service in UTT nv518G Firmware

Fri, 17 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title UTT nv518G Firmware Buffer Overflow Causing Remote Denial of Service

Thu, 16 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title UTT nv518G Firmware Buffer Overflow Causing Remote Denial of Service

Tue, 14 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Remote Buffer Overflow Causing Device Crash in UTT Firmware

Sun, 12 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Remote Buffer Overflow Causing Device Crash in UTT Firmware

Sat, 11 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Causes DoS

Fri, 10 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Causes DoS

Thu, 09 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Leading to Denial of Service

Wed, 08 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Leading to Denial of Service

Wed, 08 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Remote Buffer Overflow in UTT nv518G Firmware Leads to Denial of Service

Tue, 07 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Remote Buffer Overflow in UTT nv518G Firmware Leads to Denial of Service

Mon, 06 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title UTT nv518G Firmware Buffer Overflow Leading to Service Disruption

Sun, 05 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title UTT nv518G Firmware Buffer Overflow Leading to Service Disruption

Sat, 04 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Causes Remote Denial of Service
Weaknesses CWE-120

Sat, 04 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Causes Remote Denial of Service
Weaknesses CWE-120

Sat, 04 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Enables Remote Denial of Service
Weaknesses CWE-120

Fri, 03 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Enables Remote Denial of Service
Weaknesses CWE-120

Thu, 02 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Remote Buffer Overflow in UTT nv518G Causes Remote Denial of Service
Weaknesses CWE-120

Thu, 02 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Remote Buffer Overflow in UTT nv518G Causes Remote Denial of Service
Weaknesses CWE-120

Thu, 02 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Utt
Utt nv518g
Vendors & Products Utt
Utt nv518g

Wed, 01 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Description Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_448384 component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-02T12:38:55.333Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-52190

cve-icon Vulnrichment

Updated: 2026-07-02T12:38:49.331Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T15:15:08Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow