← back
CVE-2025-14139mediumCWE-119CWE-120

UTT 进取 520W formConfigDnsFilterGlobal strcpy buffer overflow

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.9epss 0.8%
exploitation probability
0.8%top 45% of all CVEs
observed exploitation
nono source reports it
In short

A buffer overflow vulnerability exists in UTT 进取 520W's DNS filter configuration function. An attacker can send specially crafted input to crash the device or potentially execute unauthorized code.

Technical detail

The vulnerability is a classic buffer overflow in the strcpy function within the /goform/formConfigDnsFilterGlobal endpoint, triggered via the timeRangeName parameter. An unauthenticated attacker can exploit this via network access to the affected device to cause denial of service or potential code execution; the vulnerability has been publicly disclosed.

Summary generated and translated by AI from the official description.
A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Impacted is the function strcpy of the file /goform/formConfigDnsFilterGlobal. Such manipulation of the argument timeRangeName leads to buffer overflow. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P
Affected products
UTT · 进取 520W