Impact
The vulnerability is a denial‑of‑service flaw located in the gohead/sub_44af70 component of the UTT nv518G firmware. A remote attacker can exploit the flaw by sending crafted requests, causing the device to become unresponsive. The flaw represents a resource exhaustion weakness (CWE‑400) and does not expose or modify any confidential or integral data; the impact is limited to service availability.
Affected Systems
Devices manufactured by UTT that run the nv518G model with firmware build nv518GV3v3.2.7‑210919‑161313 are affected. The issue is confined to this specific firmware version and the vulnerable component. No evidence indicates that other UTT firmware releases or products from different vendors are impacted at this time.
Risk and Exploitability
The CVSS score of 7.5 classifies the flaw as high severity. The EPSS score of less than 1 % suggests a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers who can reach the device over the Internet could trigger the bug without requiring authentication or elevated privileges, leading to a potential service outage.
OpenCVE Enrichment