CVE-2026-78169: UTT HiPER 1250GW HTTP Request aspRemoteApConfTempSend strcpy stack-based overflow
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
Which systems are affected?
UTT HiPER 1250GW devices running versions up to and including 3.2.7-210907-180535 are affected.
What access does an attacker need to exploit this issue?
The attack can be performed remotely against the HTTP request handler, but it requires low privileges. Exploitation involves manipulating the Profile argument sent to the /goform/aspRemoteApConfTempSend endpoint.
Is public exploit code available?
Yes. The exploit is public and may be used, increasing the likelihood of exploitation attempts.