CVE-2026-2118: UTT HiPER 810 rehttpd formReleaseConnect sub_4407D4 command injection
A vulnerability was determined in UTT HiPER 810 1.7.4-141218. The impacted element is the function sub4407D4 of the file /goform/formReleaseConnect of the component rehttpd. Executing a manipulation of the argument IspName can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2118?
CVE-2026-2118 is categorized as a medium severity vulnerability due to the risk of command injection.
How do I fix CVE-2026-2118?
To mitigate CVE-2026-2118, it is recommended to update the UTT HiPER 810 firmware to version 1.7.4-141219 or later.
What component is affected by CVE-2026-2118?
CVE-2026-2118 affects the rehttpd component specifically within the formReleaseConnect function.
What types of attacks can CVE-2026-2118 facilitate?
CVE-2026-2118 can allow attackers to execute arbitrary commands on the affected system, leading to potential unauthorized access.
Who is affected by CVE-2026-2118?
Users of UTT HiPER 810 version 1.7.4-141218 and earlier are susceptible to the vulnerabilities outlined in CVE-2026-2118.