CVE-2026-9627: UTT HiPER 1200GW Web Management setSysAdm strcpy buffer overflow
A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component Web Management Interface. The manipulation of the argument sysAdmUser/sysAdmPass results in buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9627?
CVE-2026-9627 has a severity rating of high, specifically 8.8.
How do I fix CVE-2026-9627?
To remediate CVE-2026-9627, upgrade the UTT HiPER 1200GW firmware to version 2.5.3-170307 or later.
What type of vulnerability is CVE-2026-9627?
CVE-2026-9627 is classified as a buffer overflow vulnerability.
Can CVE-2026-9627 be exploited remotely?
Yes, CVE-2026-9627 can be exploited remotely due to its exposure through the web management interface.
What components are affected by CVE-2026-9627?
CVE-2026-9627 affects the strcpy function in the /goform/setSysAdm file of the UTT HiPER 1200GW Web Management Interface.