Unknown · Utt 进取 518G · CVE-2025-11652
**Name of the Vulnerable Software and Affected Versions**
UTT 进取 518G versions through V3v3.2.7-210919-161313
**Description**
A buffer overflow issue exists in UTT 进取 518G. The flaw is located in the processing of the `/goform/formTaskEdit ap` API endpoint, specifically when handling the `txtMin2` argument. This allows for remote exploitation, potentially leading to arbitrary code execution or system crashes. The vendor was contacted regarding this issue but did not respond. An exploit for this issue has been publicly released.
**Recommendations**
Versions prior to V3v3.2.7-210919-161313 should be updated.
As a temporary workaround, consider restricting access to the `/goform/formTaskEdit ap` endpoint.
Avoid using the `txtMin2` parameter in the affected API endpoint until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.