CVE-2026-1137: UTT 进取 520W formWebAuthGlobalConfig strcpy buffer overflow
A vulnerability was detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /goform/formWebAuthGlobalConfig. Performing a manipulation results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1137?
CVE-2026-1137 is considered a critical vulnerability due to the potential for a buffer overflow leading to remote code execution.
How do I fix CVE-2026-1137?
To mitigate CVE-2026-1137, upgrade the UTT 进取 520W firmware to a version that addresses this buffer overflow issue.
What software versions are affected by CVE-2026-1137?
CVE-2026-1137 affects UTT 进取 520W version 1.7.7-180627.
What type of attack can exploit CVE-2026-1137?
CVE-2026-1137 can be exploited via a manipulation that results in a buffer overflow.
In which function is the CVE-2026-1137 vulnerability found?
The vulnerability CVE-2026-1137 is found in the strcpy function within the /goform/formWebAuthGlobalConfig file.