CVE-2025-14139: UTT 进取 520W formConfigDnsFilterGlobal strcpy buffer overflow
A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Impacted is the function strcpy of the file /goform/formConfigDnsFilterGlobal. Such manipulation of the argument timeRangeName leads to buffer overflow. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14139?
CVE-2025-14139 is classified as a critical severity vulnerability due to the potential for remote code execution resulting from the buffer overflow.
How do I fix CVE-2025-14139?
To fix CVE-2025-14139, update the UTT 进取 520W firmware to the latest version that addresses the buffer overflow issue.
What software is affected by CVE-2025-14139?
CVE-2025-14139 affects the UTT 进取 520W router running version 1.7.7-180627.
What type of attack is possible due to CVE-2025-14139?
CVE-2025-14139 allows attackers to exploit a buffer overflow, potentially leading to arbitrary code execution.
When was CVE-2025-14139 disclosed?
CVE-2025-14139 was publicly disclosed, allowing attackers the opportunity to exploit the vulnerability.