CVE-2026-2067: UTT 进取 520W formTimeGroupConfig strcpy buffer overflow
A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/formTimeGroupConfig. The manipulation of the argument year1 leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2067?
CVE-2026-2067 has been classified with a high severity due to the potential for remote code execution resulting from a buffer overflow.
How do I fix CVE-2026-2067?
To remediate CVE-2026-2067, update the UTT 进取 520W firmware to the latest version released by the vendor.
What are the potential impacts of CVE-2026-2067?
The exploitation of CVE-2026-2067 could lead to unauthorized access, data corruption, or complete control of affected devices.
Which software is affected by CVE-2026-2067?
CVE-2026-2067 specifically affects the UTT 进取 520W version 1.7.7-180627.
How does CVE-2026-2067 exploit vulnerability?
CVE-2026-2067 exploits a vulnerability in the strcpy function by manipulating the input to cause a buffer overflow.