CVE-2025-11355: UTT 1250GW aspChangeChannel strcpy buffer overflow
A vulnerability has been found in UTT 1250GW up to v2v3.2.2-200710. Affected by this vulnerability is the function strcpy of the file /goform/aspChangeChannel. The manipulation of the argument pvid leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11355?
CVE-2025-11355 is classified as a buffer overflow vulnerability which poses a significant security risk.
How do I fix CVE-2025-11355?
To mitigate CVE-2025-11355, update the UTT 1250GW to a version later than v2v3.2.2-200710 that addresses this vulnerability.
What products are affected by CVE-2025-11355?
CVE-2025-11355 affects the UTT 1250GW device up to version v2v3.2.2-200710.
Can CVE-2025-11355 be exploited remotely?
Yes, CVE-2025-11355 can be exploited remotely due to its nature as a buffer overflow vulnerability.
What function is vulnerable in CVE-2025-11355?
The strcpy function in the file /goform/aspChangeChannel is vulnerable in CVE-2025-11355.