CVE-2025-10757: UTT 1200GW formConfigDnsFilterGlobal buffer overflow
A weakness has been identified in UTT 1200GW up to 3.0.0-170831. The affected element is an unknown function of the file /goform/formConfigDnsFilterGlobal. This manipulation of the argument GroupName causes buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10757?
CVE-2025-10757 is classified as a high severity vulnerability due to the potential for remote exploitation and buffer overflow.
How do I fix CVE-2025-10757?
To mitigate CVE-2025-10757, users should upgrade to the latest firmware version of UTT 1200GW that addresses this vulnerability.
What are the consequences of exploiting CVE-2025-10757?
Exploitation of CVE-2025-10757 can lead to remote code execution or crashes due to the buffer overflow.
Which products are affected by CVE-2025-10757?
CVE-2025-10757 affects UTT 1200GW devices running firmware versions up to and including 3.0.0-170831.
Is remote access required to exploit CVE-2025-10757?
Yes, the vulnerability CVE-2025-10757 can be exploited remotely, making it accessible to attackers over the internet.