CVE-2026-2070: UTT 进取 520W formPolicyRouteConf strcpy buffer overflow
A vulnerability has been found in UTT 进取 520W 1.7.7-180627. The affected element is the function strcpy of the file /goform/formPolicyRouteConf. Such manipulation of the argument GroupName leads to buffer overflow. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2070?
CVE-2026-2070 is classified as a critical vulnerability due to the potential for remote code execution resulting from the buffer overflow.
How do I fix CVE-2026-2070?
To fix CVE-2026-2070, it is recommended to apply the latest firmware update provided by UTT for the 520W device.
Who is affected by CVE-2026-2070?
The vulnerability CVE-2026-2070 affects users of the UTT 进取 520W model running version 1.7.7-180627.
What is the exploit method for CVE-2026-2070?
CVE-2026-2070 can be exploited by manipulating the GroupName argument in the strcpy function, leading to a buffer overflow.
Can CVE-2026-2070 lead to data compromise?
Yes, if successfully exploited, CVE-2026-2070 can allow attackers to execute arbitrary code, potentially compromising sensitive data.