CVE-2026-4862: UTT HiPER 1250GW Parameter formConfigDnsFilterGlobal strcpy buffer overflow
A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This issue affects the function strcpy of the file /goform/formConfigDnsFilterGlobal of the component Parameter Handler. Such manipulation of the argument GroupName leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4862?
CVE-2026-4862 has been rated as critical due to its potential to cause a buffer overflow leading to arbitrary code execution.
How do I fix CVE-2026-4862?
To fix CVE-2026-4862, update UTT HiPER 1250GW to version 3.2.8 or later, which addresses this vulnerability.
What versions of UTT HiPER 1250GW are affected by CVE-2026-4862?
CVE-2026-4862 affects UTT HiPER 1250GW versions up to and including 3.2.7-210907-180535.
What is a buffer overflow in the context of CVE-2026-4862?
A buffer overflow in CVE-2026-4862 occurs when the strcpy function in the device's firmware improperly handles input data, leading to memory corruption.
Is there a workaround for CVE-2026-4862 if I cannot update immediately?
If unable to update for CVE-2026-4862, consider disabling the affected parameter handling features as a temporary mitigation.