Impact
The attack surface in UTT HiPER 1250GW's HTTP handler allows an attacker to trigger a stack-based buffer overflow by crafting an oversized pvid argument in the /goform/aspApBasicConfigUrcp endpoint. The vulnerability arises from an unbounded strcpy call that can overwrite the function’s execution stack. An attacker who can reach the target over the network can exploit this flaw to gain arbitrary code execution, potentially taking full control of the device or compromising its confidentiality, integrity, and availability.
Affected Systems
UTT HiPER 1250GW firmware versions up to 3.2.7‑210907‑180535 are vulnerable. The flaw is present only in versions prior to that release. The affected component is the HTTP handler located in /goform/aspApBasicConfigUrcp.
Risk and Exploitability
The CVSS score of 9.4 classifies this flaw as critical. EPSS is not available, but the exploit has been publicly disclosed and can be launched remotely. The vulnerability is not listed in the CISA KEV catalog, yet the public disclosure and high severity suggest that it is likely to be actively targeted. Exploitation requires network reachability to the target device and the admission of the malformed payload, but no privilege level is required on the device to trigger it.
OpenCVE Enrichment