CVE-2026-2135: UTT HiPER 810 formPdbUpConfig sub_43F020 command injection
A vulnerability was detected in UTT HiPER 810 1.7.4-141218. The impacted element is the function sub43F020 of the file /goform/formPdbUpConfig. Performing a manipulation of the argument policyNames results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2135?
CVE-2026-2135 has a high severity rating due to its command injection potential that can compromise system integrity.
How do I fix CVE-2026-2135?
To fix CVE-2026-2135, update to the latest version of UTT HiPER 810 where the vulnerability has been addressed.
What types of attacks can exploit CVE-2026-2135?
CVE-2026-2135 can be exploited through crafted HTTP requests that manipulate the argument policyNames.
Which versions of UTT HiPER 810 are affected by CVE-2026-2135?
CVE-2026-2135 affects UTT HiPER 810 version 1.7.4-141218.
What is the impact of exploiting CVE-2026-2135?
Exploiting CVE-2026-2135 may allow an attacker to execute arbitrary commands on the affected device, potentially leading to unauthorized access and control.