Impact
A stack‑based buffer overflow occurs in the strcpy function within the HTTP Request Handler at /goform/aspRemoteApConfTempSend on UTT HiPER 1250GW. By altering the Profile argument in an HTTP request, an attacker can overflow the device’s stack and potentially execute arbitrary code. The flaw is exploitable remotely and a public exploit has been released, indicating that a malicious actor can target the device from outside the network.
Affected Systems
The vulnerability affects UTT HiPER 1250GW devices running firmware versions up to 3.2.7-210907-180535. Any device with that firmware, regardless of network location, is at risk when reachable via HTTP.
Risk and Exploitability
The flaw carries a CVSS score of 9.4, placing it in the critical severity range. No EPSS score is listed, but the existence of a public exploit suggests a high likelihood of targeted attacks. The issue is not currently in the CISA KEV database. Remote exploitation is possible over HTTP, and the overflow could allow execution of arbitrary code, thereby compromising confidentiality, integrity, and availability of the device.
OpenCVE Enrichment