Impact
A buffer overflow flaw exists in the Web Management Interface of UTT HiPER 1200GW devices up to version 2.5.3-170306. The vulnerability arises when the sysAdmUser or sysAdmPass parameters supplied to the /goform/setSysAdm API are not adequately bounded, allowing an attacker to overwrite memory via the C string function strcpy, which can lead to arbitrary code execution or system compromise. This flaw is a Classic Buffer Overflow (CWE-119) and a Stack-based Buffer Overflow (CWE-120).
Affected Systems
UTT HiPER 1200GW devices running firmware up to 2.5.3‑170306. No other product versions are listed in the advisory, so older or newer releases may be unaffected. Administrators should verify the exact firmware version and compare it against the affected range.
Risk and Exploitability
The reported CVSS score of 8.7 indicates high severity, and public exploit code has been released, confirming that the vulnerability can be leveraged remotely over the network. Although the EPSS score is not available, the existence of a public exploit and the remote nature of the attack suggest a high likelihood of exploitation in environments where the device is exposed to untrusted networks. The vulnerability is not currently listed in the CISA KEV catalog, but the widespread availability of exploit code means that attackers could target any exposed device without prior knowledge of the specific firmware version.
OpenCVE Enrichment