CVE-2025-10172: UTT 750W formPictureUrl buffer overflow
A flaw has been found in UTT 750W up to 3.2.2-191225. This issue affects some unknown processing of the file /goform/formPictureUrl. Executing manipulation of the argument importpictureurl can lead to buffer overflow. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10172?
CVE-2025-10172 has a critical severity rating due to the potential for remote code execution via buffer overflow.
How do I fix CVE-2025-10172?
To fix CVE-2025-10172, upgrade the UTT 750W firmware to the latest version beyond 3.2.2-191225.
Who is affected by CVE-2025-10172?
CVE-2025-10172 affects the UTT 750W devices running firmware version up to and including 3.2.2-191225.
What does CVE-2025-10172 exploit?
CVE-2025-10172 exploits a vulnerability in the processing of the file /goform/formPictureUrl through manipulation of the argument importpictureurl.
Can CVE-2025-10172 be exploited remotely?
Yes, CVE-2025-10172 can be exploited remotely, allowing attackers to perform unauthorized actions on the affected devices.