Description
An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_44af70 component
Published: 2026-06-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a denial‑of‑service flaw in the UTT nv518G firmware. A remote attacker can target the gohead/sub_44af70 component by sending specially crafted network requests that exhaust system resources and cause the device to become unresponsive. This flaw is a classic example of CWE‑400: Uncontrolled Resource Consumption and does not expose or alter sensitive data; the impact is limited to service availability.

Affected Systems

The flaw affects UTT nv518G units running the firmware build nv518GV3v3.2.7‑210919‑161313. No other UTT firmware releases or products from other vendors are known to be impacted.

Risk and Exploitability

With a CVSS score of 7.5 the vulnerability is classified as high severity. The EPSS score of < 1 % indicates a very low probability of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. Because it can be triggered remotely without authentication or privileged access, an attacker who can reach the device over the network could potentially send repeated crafted requests to induce a service outage.

Generated by OpenCVE AI on August 2, 2026 at 01:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest UTT firmware update that corrects the gohead/sub_44af70 issue on all affected nv518G units.
  • Restrict inbound traffic to the device by configuring firewall rules or access‑control lists to allow only trusted IP addresses and required ports.
  • Monitor logs for repeated connection attempts and deploy rate‑limiting or intrusion‑detection mechanisms to mitigate potential DoS attempts.

Generated by OpenCVE AI on August 2, 2026 at 01:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via gohead/sub_44af70 in UTT nv518G firmware

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service Vulnerability in UTT nv518G Firmware via gohead/sub_44af70 Component

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service Vulnerability in UTT nv518G Firmware via gohead/sub_44af70 Component

Tue, 21 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_44af70 in UTT nv518G Firmware

Wed, 15 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_44af70 in UTT nv518G Firmware

Mon, 13 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Remote DoS via UTT nv518G Gohead Component

Sun, 12 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Remote DoS via UTT nv518G Gohead Component

Fri, 10 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Denial-of-Service Vulnerability in UTT nv518G Firmware

Wed, 08 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Denial-of-Service Vulnerability in UTT nv518G Firmware

Tue, 07 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_44af70 in UTT nv518G firmware

Mon, 06 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_44af70 in UTT nv518G firmware

Mon, 06 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_44af70 in UTT nv518G firmware

Sun, 05 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_44af70 in UTT nv518G firmware

Sat, 04 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via GoHead/Sub_44af70 in UTT nv518G Firmware

Fri, 03 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via GoHead/Sub_44af70 in UTT nv518G Firmware

Fri, 03 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_44af70 in UTT nv518G Firmware

Thu, 02 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_44af70 in UTT nv518G Firmware

Thu, 02 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_44af70 in UTT nv518G
Weaknesses CWE-119

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Utt
Utt nv518g
Vendors & Products Utt
Utt nv518g

Wed, 01 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_44af70 in UTT nv518G
Weaknesses CWE-119

Tue, 30 Jun 2026 22:45:00 +0000

Type Values Removed Values Added
Description An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_44af70 component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-01T15:15:11.023Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-52197

cve-icon Vulnrichment

Updated: 2026-07-01T15:14:52.513Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T01:30:04Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption