CVE-2026-31067: OS Command Injection
Published Apr 6, 2026
·Updated
A remote command execution (RCE) vulnerability in the /goform/formReleaseConnect component of UTT Aggressive 520W v3v1.7.7-180627 allows attackers to execute arbitrary commands via a crafted string.
Affected Software
2 affected components
All of the following
UTT 520w Firmware=1.7.7-180627
UTT 520W=3.0
Event History
Apr 6, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-31067?
CVE-2026-31067 is classified as a high severity remote command execution vulnerability.
2
How do I fix CVE-2026-31067?
To fix CVE-2026-31067, you should update the UTT Aggressive 520W firmware to the latest version provided by the vendor.
3
What are the potential impacts of CVE-2026-31067?
Exploiting CVE-2026-31067 could allow attackers to execute arbitrary commands on the affected device.
4
Which devices are affected by CVE-2026-31067?
CVE-2026-31067 affects the UTT Aggressive 520W running firmware version 1.7.7-180627.
5
Is CVE-2026-31067 an internet-facing vulnerability?
Yes, CVE-2026-31067 can be exploited remotely if the device is accessible over the internet.