CVE-2026-31059: Command Injection
Published Apr 6, 2026
·Updated
A remote command execution (RCE) vulnerability in the /goform/formDia component of UTT Aggressive HiPER 520W v3v1.7.7-180627 allows attackers to execute arbitrary commands via a crafted string.
Affected Software
2 affected components
All of the following
UTT 520w Firmware=1.7.7-180627
UTT 520W=3.0
Event History
Apr 6, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-31059?
CVE-2026-31059 is classified as a high severity vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2026-31059?
To mitigate CVE-2026-31059, users should update to the latest firmware version released by UTT that addresses this vulnerability.
3
What component is affected by CVE-2026-31059?
CVE-2026-31059 affects the /goform/formDia component of UTT Aggressive HiPER 520W version 1.7.7-180627.
4
Can CVE-2026-31059 lead to unauthorized access?
Yes, CVE-2026-31059 allows attackers to execute arbitrary commands, potentially leading to unauthorized access to the device.
5
Which versions of UTT 520W are vulnerable to CVE-2026-31059?
The vulnerable version of UTT 520W firmware is specifically 1.7.7-180627.