CVE-2026-9628: UTT HiPER 1200GW Web Management formPptpClientConfig stack-based overflow
A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /goform/formPptpClientConfig of the component Web Management Interface. This manipulation of the argument PPTP server address/username/password/tunnel name causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9628?
The severity of CVE-2026-9628 is rated high with a score of 8.8.
What is CVE-2026-9628?
CVE-2026-9628 identifies a stack-based buffer overflow vulnerability in the UTT HiPER 1200GW Web Management Interface.
How do I fix CVE-2026-9628?
To fix CVE-2026-9628, update the UTT HiPER 1200GW to version 2.5.3-170307 or later.
What systems are affected by CVE-2026-9628?
Systems affected by CVE-2026-9628 include the UTT HiPER 1200GW Web Management Interface versions up to 2.5.3-170306.
What impact does CVE-2026-9628 have?
CVE-2026-9628 can potentially allow an attacker to exploit the stack-based buffer overflow leading to unauthorized access or denial of service.