PT-2026-21023 · Unknown · Utt Hiper 520

Ruler-Chovy

·

Published

2026-02-20

·

Updated

2026-02-23

·

CVE-2026-2846

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions UTT HiPER 520 version 1.7.7-160105
Description A security issue exists in UTT HiPER 520. The sub 44D264 function within the /goform/formPdbUpConfig file of the Web Management Interface is susceptible to operating system command injection. This occurs through manipulation of the policyNames argument, and the attack can be initiated remotely. The exploit for this issue has been publicly disclosed.
Recommendations Apply a fix to the sub 44D264 function in the /goform/formPdbUpConfig file to prevent manipulation of the policyNames argument.

Exploit

Fix

Command Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-2846

Affected Products

Utt Hiper 520