PT-2025-27015 · Unknown · Utt Hiper 840G

Yuhongxiang

·

Published

2025-06-26

·

Updated

2026-01-08

·

CVE-2025-6732

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: UTT HiPER 840G versions up to 3.1.1-190328
Description: A critical issue affects the strcpy function of the /goform/setSysAdm file in the API component. The manipulation of the passwd1 argument leads to buffer overflow, allowing remote attacks. The exploit has been disclosed to the public and may be used. The vendor was contacted about this disclosure but did not respond.
Recommendations: For UTT HiPER 840G versions up to 3.1.1-190328, as a temporary workaround, consider disabling the strcpy function in the /goform/setSysAdm file of the API component until a patch is available. Restrict access to the /goform/setSysAdm API endpoint to minimize the risk of exploitation. Avoid using the passwd1 argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-02107
CVE-2025-6732

Affected Products

Utt Hiper 840G