Description
An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_445C5C component
Published: 2026-07-02
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An issue in the gohead/sub_445C5C routine of the UTT nv518G router firmware allows a remote attacker to trigger a denial of service by sending crafted requests that exhaust system resources. The weakness matches CWE‑400, and the CVSS score of 7.5 indicates that simple network access is sufficient to exploit it. When the vulnerability is triggered, the device may stop responding, disrupting network availability for any clients connected to the router.

Affected Systems

UTT nv518G routers running firmware nv518GV3v3.2.7-210919-161313 are affected. No other firmware versions are documented as vulnerable at this time.

Risk and Exploitability

The EPSS score of less than 1 % and the absence from the CISA KEV catalog suggest that public exploitation is currently unlikely. However, the high CVSS rating and the fact that the flaw is reachable over the network means that an attacker who can reach the router over its network interfaces could cause serious disruption. The likely attack vector is a remote request to the vulnerable interface that could result in a denial of service.

Generated by OpenCVE AI on July 21, 2026 at 12:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all UTT nv518G routers to the latest firmware version available from the vendor that addresses the gohead/sub_445C5C issue.
  • If a newer firmware release is not yet available, restrict traffic to the affected interface by configuring firewall rules or ACLs to allow only trusted IP addresses.
  • Continuously monitor network traffic for repeated reset events or abnormal performance, and set up alerts to detect signs of exploitation early.

Generated by OpenCVE AI on July 21, 2026 at 12:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via gohead Component in UTT nv518G Routers

Wed, 15 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via gohead Component in UTT nv518G Routers

Mon, 13 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Resource Exhaustion in UTT nv518G Router Firmware

Sun, 12 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Resource Exhaustion in UTT nv518G Router Firmware

Fri, 10 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via gohead/sub_445C5C on UTT nv518G Routers

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via gohead/sub_445C5C on UTT nv518G Routers

Thu, 09 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title UTT nv518G Router Denial of Service via gohead/sub_445C5C

Tue, 07 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title UTT nv518G Router Denial of Service via gohead/sub_445C5C

Tue, 07 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_445C5C in UTT nv518G Router Firmware

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_445C5C in UTT nv518G Router Firmware
Weaknesses CWE-400

Mon, 06 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_445C5C Component in UTT nv518G Firmware
Weaknesses CWE-400

Sun, 05 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_445C5C Component in UTT nv518G Firmware
Weaknesses CWE-400

Sat, 04 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via gohead/sub_445C5C in UTT nv518G Firmware
Weaknesses CWE-400

Sat, 04 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via gohead/sub_445C5C in UTT nv518G Firmware
Weaknesses CWE-400

Fri, 03 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_445C5C in UTT nv518G Firmware
Weaknesses CWE-400

Fri, 03 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_445C5C in UTT nv518G Firmware
Weaknesses CWE-400

Thu, 02 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Utt
Utt nv518g
Vendors & Products Utt
Utt nv518g

Thu, 02 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_445C5C component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-06T14:47:26.371Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-52192

cve-icon Vulnrichment

Updated: 2026-07-06T14:47:18.329Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T12:45:02Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption