← back
CVE-2025-13442mediumCWE-74CWE-77

UTT 进取 750W formPdbUpConfig system command injection

18Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.9epss 20%
exploitation probability
20%top 3% of all CVEs
observed exploitation
nono source reports it
In short

A web interface in UTT 进取 750W devices allows attackers to inject system commands through a form parameter called policyNames. An attacker can remotely execute arbitrary commands on the device without needing authentication.

Technical detail

CWE-74/CWE-77 command injection vulnerability in the /goform/formPdbUpConfig endpoint allows unauthenticated remote code execution via unsanitized policyNames parameter. The vulnerability affects UTT 进取 750W up to version 3.2.2-191225 and requires only network access to exploit; no authentication is required.

Summary generated and translated by AI from the official description.
A security vulnerability has been detected in UTT 进取 750W up to 3.2.2-191225. Affected by this vulnerability is the function system of the file /goform/formPdbUpConfig. Such manipulation of the argument policyNames leads to command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
UTT · 进取 750W