← back
CVE-2025-6098criticalCWE-119CWE-120

UTT 进取 750W API setSysAdm strcpy buffer overflow

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.3epss 1.2%
exploitation probability
1.2%top 34% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability was found in UTT 进取 750W up to 5.0. It has been classified as critical. This affects the function strcpy of the file /goform/setSysAdm of the component API. The manipulation of the argument passwd1 leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Affected products
UTT · 进取 750W
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.