PT-2026-6938 · Unknown · Utt Hiper 810
Cha0Yang
·
Publicado
2026-02-08
·
Atualizado
2026-02-13
·
CVE-2026-2118
CVSS v2.0
8.3
Alta
| Vetor | AV:N/AC:L/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
UTT HiPER 810 version 1.7.4-141218
Description
A flaw exists in the rehttpd component of UTT HiPER 810. Specifically, the
sub 4407D4 function within the /goform/formReleaseConnect file is susceptible to command injection. Manipulating the Isp Name argument can allow for remote execution of commands. The exploit for this issue has been publicly disclosed.Recommendations
Apply updates to address the vulnerability in the
sub 4407D4 function of the /goform/formReleaseConnect file.
As a temporary workaround, restrict or disable the use of the Isp Name argument.Exploit
Correção
Command Injection
Special Elements Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Utt Hiper 810