Impact
A buffer overflow exists in the strcpy function that processes the Profile argument in the formTaskEdit_ap endpoint of the UTT HiPER 1250GW device. By supplying an oversized input, an attacker can cause memory corruption that may lead to arbitrary code execution or denial of service. The flaw resides in unvalidated input handling and is classified as CWE‑119 and CWE‑120.
Affected Systems
The vulnerability affects UTT HiPER 1250GW equipment running firmware up to version 3.2.7‑210907‑180535. Any device with this firmware or earlier is potentially vulnerable. Later firmware releases are not known to be affected.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. No EPSS score is available, but the vulnerability is publicly documented and an exploit is available, suggesting that exploitation could occur. The flaw can be triggered remotely over the network by accessing the formTaskEdit_ap interface. The device is listed as not in the CISA KEV catalog. Attackers with network access to the device could potentially execute malicious code via this pathway.
OpenCVE Enrichment