Stack-Based Buffer Overflow in UTT HiPER 1250GW by UTT
CVE-2026-18895
Key Information:
- Vendor
Utt
- Status
- Vendor
- CVE Published:
- 5 August 2026
Badges
What is CVE-2026-18895?
A vulnerability exists in the UTT HiPER 1250GW, affecting versions up to 3.2.7-210907-180535. The flaw is found in the strcpy function within the /goform/APSecurity_5g file, which leads to a stack-based buffer overflow when the argument cipher is manipulated. This vulnerability allows for remote exploitation, potentially enabling attackers to execute arbitrary code. The issue has been publicly disclosed, and despite attempts to inform the vendor, there has been no response regarding a fix or mitigation.
Affected Version(s)
HiPER 1250GW 3.2.7-210907-180535
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
