CVE-2025-15461: UTT 进取 520W formTaskEdit strcpy buffer overflow
A flaw has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/formTaskEdit. Executing a manipulation of the argument selDateType can lead to buffer overflow. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15461?
CVE-2025-15461 has been classified as a medium severity vulnerability due to the potential for remote buffer overflow exploits.
How do I fix CVE-2025-15461?
To fix CVE-2025-15461, it is recommended to update the UTT 进取 520W firmware to a version that addresses this vulnerability.
What type of attack does CVE-2025-15461 facilitate?
CVE-2025-15461 allows attackers to execute a remote buffer overflow by manipulating the selDateType argument.
Which product is affected by CVE-2025-15461?
CVE-2025-15461 affects the UTT 进取 520W version 1.7.7-180627.
Is CVE-2025-15461 easy to exploit?
Yes, CVE-2025-15461 is considered easy to exploit remotely, which increases the risk for affected users.