PT-2025-25508 · Utt · Utt 进取 750W

Newym

·

Published

2025-06-16

·

Updated

2025-06-21

·

CVE-2025-6098

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UTT 进取 750W versions up to 5.0
Description A critical issue affects the strcpy function of the /goform/setSysAdm component API. The manipulation of the passwd1 argument leads to a buffer overflow. This issue can be exploited remotely.
Recommendations For UTT 进取 750W versions up to 5.0, as a temporary workaround, consider disabling the strcpy function in the /goform/setSysAdm API endpoint until a patch is available. Restrict access to the /goform/setSysAdm endpoint to minimize the risk of exploitation. Avoid using the passwd1 argument in the affected API endpoint until the issue is resolved.

Exploit

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-6098

Affected Products

Utt 进取 750W