CVE-2026-7420 PUBLISHED

UTT HiPER 1250GW ConfigAdvideo strcpy buffer overflow

Assigner: VulDB
Reserved: 29.04.2026 Published: 29.04.2026 Updated: 29.04.2026

A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file route/goform/ConfigAdvideo. The manipulation of the argument Profile results in buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
CVSS Score: 8.7

Product Status

Vendor UTT
Product HiPER 1250GW
Versions
  • Version 3.2.7-210907-180535 is affected

Credits

  • maple_s (VulDB User) reporter

References

Problem Types

  • Buffer Overflow CWE
  • Memory Corruption CWE