CVE-2025-15091: UTT 进取 512W formPictureUrl strcpy buffer overflow
A vulnerability was determined in UTT 进取 512W up to 1.7.7-171114. This issue affects the function strcpy of the file /goform/formPictureUrl. This manipulation of the argument importpictureurl causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15091?
CVE-2025-15091 has been assessed with a high severity due to the potential for remote exploitation and buffer overflow vulnerabilities.
How do I fix CVE-2025-15091?
To fix CVE-2025-15091, update the UTT 进取 512W firmware to a version later than 1.7.7-171114.
What is the impact of CVE-2025-15091?
The impact of CVE-2025-15091 includes the ability for an attacker to execute arbitrary code on affected devices through a buffer overflow.
Which versions are affected by CVE-2025-15091?
CVE-2025-15091 affects UTT 进取 512W versions up to and including 1.7.7-171114.
Can CVE-2025-15091 be exploited remotely?
Yes, CVE-2025-15091 can be exploited remotely due to vulnerable code in the device's handling of input.