PT-2025-50967 · Unknown · Utt 进取 512W
Alc9700
·
Published
2025-12-12
·
Updated
2025-12-13
·
CVE-2025-14572
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
UTT 进取 512W versions through 1.7.7-171114
Description
A flaw exists in UTT 进取 512W up to version 1.7.7-171114. Manipulation of the
hidcontact argument in the '/goform/formWebAuthGlobalConfig' path can lead to memory corruption. Remote exploitation is possible, and an exploit has been publicly released. The vendor was notified but did not respond.Recommendations
Versions prior to 1.7.7-171114 should be updated. As a temporary workaround, restrict access to the '/goform/formWebAuthGlobalConfig' path. Avoid manipulating the
hidcontact argument.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Utt 进取 512W