Impact
A buffer overflow flaw exists in the UTT HiPER 1200GW firmware, located in the strcpy call within the /goform/formConfigFastDirectionW file. Manipulating the ssid argument allows an attacker to overflow a local buffer, which can result in unpredictable device behavior or a crash. The vulnerability is classified under CWE-119 and CWE-120 and is most severe when the ssid string exceeds the buffer’s capacity.
Affected Systems
This issue affects UTT HiPER 1200GW firmware versions up to 2.5.3-170306. Any deployed device running an affected firmware build is vulnerable to remote exploitation if it accepts external ssid input through the formConfigFastDirectionW interface.
Risk and Exploitability
The CVSS score of 8.7 indicates a high risk to confidentiality, integrity, and availability. No EPSS information is presently available, but published exploits demonstrate that the flaw can be triggered remotely without special privileges. The vulnerability is not listed in the CISA KEV catalog, yet its remote nature and the existence of a public exploit make it a serious concern.
OpenCVE Enrichment