Impact
The vulnerability is a denial‑of‑service flaw in the UTT nv518G firmware. A remote attacker can target the gohead/sub_44af70 component by sending specially crafted network requests that exhaust system resources and cause the device to become unresponsive. This flaw is a classic example of CWE‑400: Uncontrolled Resource Consumption and does not expose or alter sensitive data; the impact is limited to service availability.
Affected Systems
The flaw affects UTT nv518G units running the firmware build nv518GV3v3.2.7‑210919‑161313. No other UTT firmware releases or products from other vendors are known to be impacted.
Risk and Exploitability
With a CVSS score of 7.5 the vulnerability is classified as high severity. The EPSS score of < 1 % indicates a very low probability of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. Because it can be triggered remotely without authentication or privileged access, an attacker who can reach the device over the network could potentially send repeated crafted requests to induce a service outage.
OpenCVE Enrichment