CVE-2025-15090: UTT 进取 512W formConfigNoticeConfig strcpy buffer overflow
A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This vulnerability affects the function strcpy of the file /goform/formConfigNoticeConfig. The manipulation of the argument timestart results in buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15090?
CVE-2025-15090 is classified as a serious vulnerability due to its potential for remote exploitation and the risk of buffer overflow.
How do I fix CVE-2025-15090?
To fix CVE-2025-15090, update the UTT 进取 512W firmware to a version later than 1.7.7-171114.
What software is affected by CVE-2025-15090?
CVE-2025-15090 affects UTT 进取 512W versions up to and including 1.7.7-171114.
What kind of attack can exploit CVE-2025-15090?
An attacker can exploit CVE-2025-15090 through a remote buffer overflow attack.
What functions are involved in CVE-2025-15090?
The vulnerability in CVE-2025-15090 specifically involves the strcpy function in the /goform/formConfigNoticeConfig file.