Impact
A stack‑based buffer overflow exists in the UTT HiPER 1200GW Web Management Interface, triggered by manipulating the PPTP server address, username, password, or tunnel name via the formPptpClientConfig endpoint. The vulnerability can be leveraged remotely to overwrite critical control data on the stack, potentially allowing an attacker to execute arbitrary code on the affected device. The description from the vulnerability report does not explicitly state the consequences, but a stack overflow of this nature typically implies high risk to confidentiality, integrity, and availability.
Affected Systems
The affected product is UTT HiPER 1200GW up to version 2.5.3-170306. The weakness resides in the /goform/formPptpClientConfig file of the Web Management Interface, and no other versions are listed as affected.
Risk and Exploitability
The CVSS score is 8.7, indicating a high severity. EPSS is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The attack can be initiated remotely, and the vulnerability has publicly available exploits, which raises the tangible risk of compromise. An attacker who can reach the vulnerable endpoint could gain full remote control of the device if the overflow is exploitable.
OpenCVE Enrichment