CVE-2025-14535
UTT 进取 512W formConfigFastDirectionW strcpy buffer overflow
In short
A buffer overflow vulnerability exists in UTT 进取 512W devices where an attacker can send a specially crafted request to the /goform/formConfigFastDirectionW function with an overly long SSID parameter, potentially crashing the device or executing arbitrary code remotely.
Technical detail
The vulnerability is a classic stack-based buffer overflow (CWE-119, CWE-120) in the strcpy function within the formConfigFastDirectionW endpoint, triggered by unsanitized ssid parameter input. Remote unauthenticated attackers can exploit this without preconditions to achieve denial of service or code execution on affected UTT 进取 512W devices up to version 3.1.7.7-171114.
Summary generated and translated by AI from the official description.
A vulnerability was identified in UTT 进取 512W up to 3.1.7.7-171114. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. The manipulation of the argument ssid leads to buffer overflow. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Affected products
UTT · 进取 512Wpublic PoCs found — 1
cve_referencegithub.com/maximdevere/CVE2/issues/7unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →