Impact
The CVE documents a buffer overflow (CWE‑120) in the gohead/sub_416f28 component of UTT’s nv518G firmware nv518GV3v3.2.7‑210919‑161313. The overflow occurs when the component processes crafted input from a remote source, corrupting memory and causing the component to crash. The crash results in a denial of service, but the description does not claim that the attacker gains code execution or other privileges.
Affected Systems
The affected product is the UTT nv518G series router, specifically firmware version nv518GV3v3.2.7‑210919‑161313. No broader version range is indicated, so only this build is known to host the flaw.
Risk and Exploitability
The vulnerability may be triggered remotely by sending a specially constructed packet to the gohead component, which is reachable over the network. The CVSS score of 7.5 indicates high severity, but the EPSS score of less than 1% means the probability of exploitation is very low. The vulnerability is not listed in CISA’s KEV catalog. With no public exploit at the time, the main threat is periodic service outages rather than data compromise.
OpenCVE Enrichment