Utt · Utt · CVE-2025-11323
**Name of the Vulnerable Software and Affected Versions**
UTT versions prior to v2v3.2.2-200710
**Description**
A buffer overflow issue exists in the `strcpy` function within the `/goform/formUserStatusRemark` file. Manipulation of the `Username` argument can trigger this issue, potentially allowing for remote exploitation. The exploit for this issue has been publicly disclosed.
**Recommendations**
Versions prior to v2v3.2.2-200710 should be updated. As a temporary workaround, consider restricting access to the `/goform/formUserStatusRemark` file to minimize the risk of exploitation. Avoid using the `Username` parameter in the affected API endpoint until the issue is resolved.