Description
Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_444C8C component
Published: 2026-07-02
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer overflow exists in the GoHead component (sub_444C8C) of the UTT nv518G firmware version nv518GV3v3.2.7‑210919‑161313. The overflow corrupts memory and crashes the service, causing the device to become unresponsive. Because the flaw merely disrupts operation, it does not grant attackers the ability to gain control; a loss of availability.

Affected Systems

The affected system is the UTT518G router running firmware nv518GV3v3.2.7‑210919‑161313. The CVE data does not specify additional vulnerable firmware revisions, so the scope is limited to the aforementioned release.

Risk and Exploitability

The CVSS score of 7.5 classifies this issue as high severity, while the EPSS score of less than 1% suggests a very low probability that exploit code will be available in the wild. This vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote over the network, most likely targeting the GoHead service, and that no authentication is required to trigger the crash. Though the impact is limited to availability, repeated denial‑of‑service attacks could disrupt services or necessitate costly device restarts.

Generated by OpenCVE AI on July 22, 2026 at 13:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the UTT nv518G firmware to a release that includes the buffer‑overflow fix, if a vendor patch is available.
  • Block or limit external access to the GoHead service with a firewall or network segmentation, allowing only trusted hosts to reach the device.
  • Disable or remove any superfluous remote services or features so that the attack surface around the vulnerable component is minimized.
  • Continually monitor device logs for evidence of repeated crashes or abnormal events related to the GoHead component, and set alerts to notify administrators of potential exploitation attempts.

Generated by OpenCVE AI on July 22, 2026 at 13:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in GoHead Service Causes Denial of Service on UTT518G Router

Fri, 17 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in GoHead Service Causes Denial of Service on UTT518G Router

Wed, 15 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G GoHead Component Causes Remote Denial of Service

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G GoHead Component Causes Remote Denial of Service

Sun, 12 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title UTT nv518G Buffer Overflow Denial of Service Vulnerability

Sat, 11 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title UTT nv518G Buffer Overflow Denial of Service Vulnerability

Fri, 10 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G GoHead Component Causes Remote Denial of Service

Thu, 09 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G GoHead Component Causes Remote Denial of Service

Thu, 09 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Enables Remote DoS via GoHead Component

Wed, 08 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Enables Remote DoS via GoHead Component

Wed, 08 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Causing Remote Denial of Service

Tue, 07 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Causing Remote Denial of Service

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Leads to Remote Denial of Service
Weaknesses CWE-120

Sun, 05 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Leads to Remote Denial of Service
Weaknesses CWE-120

Sun, 05 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Causes Denial of Service
Weaknesses CWE-119
CWE-120

Sat, 04 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Causes Denial of Service
Weaknesses CWE-119
CWE-120

Sat, 04 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Allows Remote Denial of Service
Weaknesses CWE-119

Fri, 03 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in UTT nv518G Firmware Allows Remote Denial of Service
Weaknesses CWE-119

Fri, 03 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Buffer Overflow in UTT nv518G Device Firmware
Weaknesses CWE-120
CWE-787

Fri, 03 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Buffer Overflow in UTT nv518G Device Firmware
Weaknesses CWE-120
CWE-787

Thu, 02 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Utt
Utt nv518g
Vendors & Products Utt
Utt nv518g

Thu, 02 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_444C8C component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-06T14:48:36.449Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-52191

cve-icon Vulnrichment

Updated: 2026-07-06T14:48:27.295Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T14:00:04Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')