CVE-2026-10292: UTT HiPER 1200GW formTaskEdit strcpy stack-based overflow
A vulnerability was detected in UTT HiPER 1200GW up to 2.5.3-170306. This affects the function strcpy of the file /goform/formTaskEdit. The manipulation results in stack-based buffer overflow. The attack may be launched remotely. The exploit is now public and may be used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Block access to the UTT HiPER 1200GW management interface from untrusted networks. At the network perimeter/firewall, deny WAN/internet access to the device and allow management only from specific trusted IP addresses.
- Compensating control
Deploy a WAF or HTTP filtering rule to block or drop requests targeting the path /goform/formTaskEdit (and/or requests that contain suspiciously long parameters) to prevent exploitation of the strcpy stack-based overflow.
- Operational
Isolate affected UTT HiPER 1200GW devices from operational networks until a vendor-provided fix is obtained and applied.
- Operational
Contact the device vendor or support to obtain any available firmware updates or mitigations and apply vendor-supplied patches as soon as they are released.
- Operational
Monitor device logs, IDS/IPS, and HTTP access logs for signs of exploitation (including requests to /goform/formTaskEdit and any crashes or anomalous behavior) and investigate/contain any suspected compromises. The exploit is public and may be used in the wild.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10292?
The severity of CVE-2026-10292 is classified as high, with a score of 7.4.
How do I fix CVE-2026-10292?
To fix CVE-2026-10292, upgrade the UTT HiPER 1200GW firmware to version 2.5.3-170307 or later.
What type of vulnerability is CVE-2026-10292?
CVE-2026-10292 is a stack-based buffer overflow vulnerability.
Can CVE-2026-10292 be exploited remotely?
Yes, CVE-2026-10292 can be exploited remotely.
What components are affected by CVE-2026-10292?
CVE-2026-10292 affects the strcpy function within the /goform/formTaskEdit file in UTT HiPER 1200GW.