CVE-2025-14140: UTT 进取 520W websHostFilter strcpy buffer overflow
A vulnerability was detected in UTT 进取 520W 1.7.7-180627. The affected element is the function strcpy of the file /goform/websHostFilter. Performing manipulation of the argument addHostFilter results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14140?
CVE-2025-14140 has a high severity due to the potential for remote exploitation through a buffer overflow.
How do I fix CVE-2025-14140?
To fix CVE-2025-14140, update the UTT 进取 520W firmware to the latest version that addresses this vulnerability.
What systems are affected by CVE-2025-14140?
CVE-2025-14140 affects the UTT 进取 520W router running version 1.7.7-180627.
What is the impact of exploiting CVE-2025-14140?
Exploiting CVE-2025-14140 could allow an attacker to execute arbitrary code on the affected device.
Is CVE-2025-14140 exploitable remotely?
Yes, CVE-2025-14140 is remotely exploitable, allowing attackers to target the device over the network.