CVE-2026-2068: UTT 进取 520W formSyslogConf strcpy buffer overflow
A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/formSyslogConf. The manipulation of the argument ServerIp results in buffer overflow. The attack may be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2068?
CVE-2026-2068 has been identified as a critical vulnerability due to its potential for remote exploitation and buffer overflow risks.
How do I fix CVE-2026-2068?
To fix CVE-2026-2068, upgrade UTT 进取 520W firmware to a version that is not affected, specifically beyond version 1.7.7-180627.
What does CVE-2026-2068 affect?
CVE-2026-2068 affects the strcpy function in the /goform/formSyslogConf of UTT 进取 520W versions 1.7.7-180627.
Who can exploit CVE-2026-2068?
CVE-2026-2068 can be exploited remotely by attackers who can manipulate the ServerIp argument.
What are the potential consequences of CVE-2026-2068?
The consequences of CVE-2026-2068 include unauthorized access, system crashes, or execution of arbitrary code due to buffer overflow.