Impact
A weakness has been identified in UTT HiPER 1200GW firmware versions up to 2.5.3-170306 that involves the strcpy function in the /goform/formGroupConfig module. Manipulating the timestart argument can cause a stack-based buffer overflow, potentially allowing attackers to overwrite stack memory. This overflow is a CWE-119 and CWE-121 vulnerability. While the documentation states that the flaw could be used for attacks, it does not explicitly confirm arbitrary code execution; based on the type of overflow, it is inferred that an attacker could gain arbitrary code execution capability.
Affected Systems
UTT’s HiPER 1200GW network appliances running firmware versions up to and including 2.5.3-170306 are vulnerable. No newer revisions are listed as affected, so users should verify they are on a version newer than 2.5.3-170306.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. EPSS data is not available. The vulnerability can be triggered from remote over the web interface, and a public exploit has been released, implying a tangible risk. The device is not listed in CISA’s KEV catalog, but the combination of remote attack vector and publicly available exploit elevates the urgency of remediation.
OpenCVE Enrichment