Impact
Buffer overflow in the gohead/sub_447CAC component of UTT 518G firmware nv518GV3v3.2.7-210919-161313 allows a remote attacker to trigger a device reboot or halt, resulting in a Denial of Service. The flaw, catalogued as CWE-120, permits the attacker to overwrite adjacent memory and crash the process.
Affected Systems
UTT model 518G devices running firmware nv518GV3v3.2.7-210919-161313 contain the vulnerable gohead/sub_447CAC module.
Risk and Exploitability
CVSS score of 7.5 indicates a high severity vulnerability, while an EPSS score of less than 1% suggests that the likelihood of exploitation in the wild is very low. The flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote over the network; an attacker would need packets directed to the gohead/sub_447CAC component to trigger the buffer overflow and cause the device to reboot or stop responding.
OpenCVE Enrichment