PT-2025-41740 · Unknown · Utt 进取 518G

Cymiao

+1

·

Published

2025-10-13

·

Updated

2026-01-08

·

CVE-2025-11652

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions UTT 进取 518G versions through V3v3.2.7-210919-161313
Description A buffer overflow issue exists in UTT 进取 518G. The flaw is located in the processing of the /goform/formTaskEdit ap API endpoint, specifically when handling the txtMin2 argument. This allows for remote exploitation, potentially leading to arbitrary code execution or system crashes. The vendor was contacted regarding this issue but did not respond. An exploit for this issue has been publicly released.
Recommendations Versions prior to V3v3.2.7-210919-161313 should be updated. As a temporary workaround, consider restricting access to the /goform/formTaskEdit ap endpoint. Avoid using the txtMin2 parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11652

Affected Products

Utt 进取 518G