Impact
A stack-based buffer overflow exists in the UTT HiPER 1250GW Web Management interface, specifically in the strcpy call within the /goform/formConfigFastDirectionW component. Manipulating the Profile argument can overflow the stack, and based on the description, it is inferred that an attacker can achieve arbitrary code execution on the device. The vulnerability is identified as CWE-119 and CWE-121.
Affected Systems
Products affected include UTT HiPER 1250GW firmware versions up to 3.2.7-210907-180535. All earlier builds that use the vulnerable web management interface are susceptible, while newer firmware releases may provide a fix.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. EPSS information is not available, and the vulnerability is publicly disclosed and can be exploited remotely through the web interface. It is listed in no KEV catalog. The likely attack vector is a remote attacker submitting a crafted request containing an oversized Profile argument to the /goform/formConfigFastDirectionW endpoint.
OpenCVE Enrichment