Impact
The vulnerability is a classic buffer overflow in the strcpy implementation within the formNatStaticMap handler. By providing a specially crafted NatBind argument, an attacker can overflow the fixed‑size buffer, corrupting adjacent memory. Depending on the firmware’s memory layout, this could allow arbitrary code execution or destabilize the device, potentially exposing sensitive configuration or control. The weakness is a classic stack buffer overflow (CWE‑119) and related to unsafe string handling (CWE‑120).
Affected Systems
The flaw affects all UTT HiPER 1200GW appliances running firmware versions up to 2.5.3‑170306. Devices manufactured or sold by UTT under the HiPER 1200GW line are impacted. No other vendors or versions are explicitly listed. The attack vector is remote, as the vulnerable endpoint is accessible over the management interface.
Risk and Exploitability
The CVSS base score is 8.7, indicating high severity. EPSS data is unavailable, but public disclosures and code are already available, implying the exploit is likely to be used by malicious actors. Because the vulnerability is remote and the exploit can be crafted with standard tools, the operational risk is high for any exposed HiPER 1200GW device. KEV does not list it, but the public presence suggests a real threat.
OpenCVE Enrichment