Buffer Overflow Vulnerability in UTT 1200GW by UTT
CVE-2025-10170
Key Information:
Badges
What is CVE-2025-10170?
A security vulnerability has been identified in UTT 1200GW devices, specifically in the function sub_4B48F8 of the /goform/formApLbConfig file. This vulnerability arises from improper handling of the loadBalanceNameOld argument, leading to a potential buffer overflow scenario. Attackers can exploit this vulnerability to execute remote attacks. Despite disclosure attempts to the vendor, no response has been received, indicating a potential lack of mitigation or acknowledgment of this serious security flaw.
Affected Version(s)
1200GW 3.0.0-170831
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved