Buffer Overflow Vulnerability in UTT 1250GW Router
CVE-2025-11355
Key Information:
Badges
What is CVE-2025-11355?
A buffer overflow vulnerability has been identified in the UTT 1250GW router software prior to version v2v3.2.2-200710. This flaw resides in the strcpy function within the /goform/aspChangeChannel file, where improper handling of the pvid argument can lead to a buffer overflow. This vulnerability allows remote attackers to exploit the system, which poses a significant security risk. Despite early communication with the vendor regarding this finding, no response has been received, leaving systems vulnerable to potential exploitation.
Affected Version(s)
1250GW v2v3.2.2-200710
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved