Impact
A buffer overflow occurs in the strcpy function within the /goform/formNatStaticMap component of UTT HiPER 1250GW, triggered by manipulating the NatBind argument. The flaw can allow a remote attacker to overflow the buffer, potentially enabling arbitrary code execution. The weakness corresponds to CWE‑119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE‑120 (Buffer Copy without Checking Size of Input).
Affected Systems
UTT HiPER 1250GW firmware versions up to 3.2.7‑210907‑180535 are vulnerable. This includes all installations of the hardware unit running the affected firmware and any devices that rely on the formNatStaticMap functionality.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, indicating a high severity. No EPSS score is reported, and it is not listed in the CISA KEV catalog, but the exploit is public and can be executed remotely by manipulating NatBind. Attackers with network access to the device’s administrative interface can trigger the overflow and may gain code execution.
OpenCVE Enrichment