Description
An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_44af70 component
Published: 2026-06-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a denial‑of‑service flaw located in the gohead/sub_44af70 component of the UTT nv518G firmware. A remote attacker can exploit the flaw by sending crafted requests, causing the device to become unresponsive. The flaw represents a resource exhaustion weakness (CWE‑400) and does not expose or modify any confidential or integral data; the impact is limited to service availability.

Affected Systems

Devices manufactured by UTT that run the nv518G model with firmware build nv518GV3v3.2.7‑210919‑161313 are affected. The issue is confined to this specific firmware version and the vulnerable component. No evidence indicates that other UTT firmware releases or products from different vendors are impacted at this time.

Risk and Exploitability

The CVSS score of 7.5 classifies the flaw as high severity. The EPSS score of less than 1 % suggests a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers who can reach the device over the Internet could trigger the bug without requiring authentication or elevated privileges, leading to a potential service outage.

Generated by OpenCVE AI on July 15, 2026 at 11:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest UTT firmware revision that fixes the gohead/sub_44af70 bug on all affected nv518G units.
  • Limit inbound traffic to the device with a firewall or access‑control list to trusted sources and required ports, thereby reducing the attack surface.
  • Enable logging and monitoring of abnormal request patterns or sustained traffic spikes to detect and respond to attempted denial‑of‑service attacks.

Generated by OpenCVE AI on July 15, 2026 at 11:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_44af70 in UTT nv518G Firmware

Mon, 13 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Remote DoS via UTT nv518G Gohead Component

Sun, 12 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Remote DoS via UTT nv518G Gohead Component

Fri, 10 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Denial-of-Service Vulnerability in UTT nv518G Firmware

Wed, 08 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Denial-of-Service Vulnerability in UTT nv518G Firmware

Tue, 07 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_44af70 in UTT nv518G firmware

Mon, 06 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_44af70 in UTT nv518G firmware

Mon, 06 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_44af70 in UTT nv518G firmware

Sun, 05 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_44af70 in UTT nv518G firmware

Sat, 04 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via GoHead/Sub_44af70 in UTT nv518G Firmware

Fri, 03 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via GoHead/Sub_44af70 in UTT nv518G Firmware

Fri, 03 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_44af70 in UTT nv518G Firmware

Thu, 02 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_44af70 in UTT nv518G Firmware

Thu, 02 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_44af70 in UTT nv518G
Weaknesses CWE-119

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Utt
Utt nv518g
Vendors & Products Utt
Utt nv518g

Wed, 01 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via gohead/sub_44af70 in UTT nv518G
Weaknesses CWE-119

Tue, 30 Jun 2026 22:45:00 +0000

Type Values Removed Values Added
Description An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_44af70 component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-01T15:15:11.023Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-52197

cve-icon Vulnrichment

Updated: 2026-07-01T15:14:52.513Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-15T11:30:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption