Impact
The flaw is a stack‑based buffer overflow that occurs when the UTT HiPER 1250GW device processes the 'Profile' input in its NTP configuration interface (route/goform/NTP). The vulnerability is triggered by executing a crafted strcpy function, which can overwrite adjacent memory and allow an attacker to run arbitrary code on the device. It is a classic CWE‑119/CWE‑120 type defect that can compromise confidentiality, integrity, and availability.
Affected Systems
UTT HiPER 1250GW devices with firmware version 3.2.7‑210907‑180535 or earlier are affected. No other firmware revisions have been reported as vulnerable.
Risk and Exploitability
The CVSS score of 8.7 classifies the issue as high severity. The EPSS score is not provided, but the disclosure notes that the exploit is publicly available and can be used remotely, suggesting a realistic exploitation probability. The vulnerability is not present in the CISA KEV catalog. Attackers can launch the exploit from outside the local network by sending a manipulated NTP profile to the exposed interface, without requiring local or privileged access.
OpenCVE Enrichment