PT-2026-36022 · Utt · Hiper 1250Gw
Maple_S
·
Published
2026-04-29
·
Updated
2026-04-30
·
CVE-2026-7420
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
UTT HiPER 1250GW versions prior to 3.2.7-210907-180535
Description
A buffer overflow exists in the
strcpy() function within the 'route/goform/ConfigAdvideo' file. This issue allows a remote attacker to trigger the flaw by manipulating the Profile argument. A buffer overflow occurs when a program writes more data to a storage area (buffer) than it can hold, potentially leading to crashes or unauthorized code execution.Recommendations
Update to a version later than 3.2.7-210907-180535.
As a temporary workaround, restrict access to the 'route/goform/ConfigAdvideo' endpoint or avoid using the
Profile argument until a patch is applied.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hiper 1250Gw