CVE-2026-0840: UTT 进取 520W formConfigNoticeConfig strcpy buffer overflow
A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this vulnerability is the function strcpy of the file /goform/formConfigNoticeConfig. The manipulation of the argument timestart leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-0840?
CVE-2026-0840 has a high severity due to the potential for remote code execution through a buffer overflow.
How do I fix CVE-2026-0840?
To fix CVE-2026-0840, update the UTT 进取 520W firmware to the latest version that addresses this vulnerability.
What systems are affected by CVE-2026-0840?
CVE-2026-0840 affects UTT 进取 520W devices running version 1.7.7-180627.
What type of vulnerability is CVE-2026-0840?
CVE-2026-0840 is a buffer overflow vulnerability that occurs in the strcpy function.
Can CVE-2026-0840 be exploited remotely?
Yes, CVE-2026-0840 can be exploited remotely, allowing attackers to execute arbitrary code on the affected device.