PT-2026-6938 · Unknown · Utt Hiper 810
Cha0Yang
·
Published
2026-02-08
·
Updated
2026-02-13
·
CVE-2026-2118
CVSS v2.0
8.3
High
| Vector | AV:N/AC:L/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
UTT HiPER 810 version 1.7.4-141218
Description
A flaw exists in the rehttpd component of UTT HiPER 810. Specifically, the
sub 4407D4 function within the /goform/formReleaseConnect file is susceptible to command injection. Manipulating the Isp Name argument can allow for remote execution of commands. The exploit for this issue has been publicly disclosed.Recommendations
Apply updates to address the vulnerability in the
sub 4407D4 function of the /goform/formReleaseConnect file.
As a temporary workaround, restrict or disable the use of the Isp Name argument.Exploit
Fix
Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Utt Hiper 810