Impact
Buffer overflow in the gohead/sub_447CAC component of UTT nv518G firmware (nv518GV3v3.2.7-210919-161313) allows a remote attacker to cause a device reboot or stop responding, disrupting network services. This classic CWE‑120 flaw arises from insufficient input validation, enabling an attacker to overwrite memory and trigger a crash.
Affected Systems
UTT model 518G devices running firmware nv518GV3v3.2.7-210919-161313 contain the vulnerable gohead/sub_447CAC module.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score of less than 1% shows a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote over the network, with an attacker needing to send a specifically crafted packet or payload to trigger the overflow and cause a device reboot or crash.
OpenCVE Enrichment