← Voltar para CVEs
CVE-2026-1162
CRITICAL9.8
Descricao
A flaw has been found in UTT HiPER 810 1.7.4-141218. The impacted element is the function strcpy of the file /goform/setSysAdm. This manipulation of the argument passwd1 causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Detalhes CVE
Pontuacao CVSS v3.19.8
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado1/19/2026
Ultima modificacao2/6/2026
Fontenvd
Avistamentos honeypot0
Produtos afetados
utt:810utt:810_firmware
Fraquezas (CWE)
CWE-119CWE-120
Referencias
https://github.com/cha0yang1/UTT810/blob/main/1.md(cna@vuldb.com)
https://github.com/cha0yang1/UTT810/blob/main/1.md#poc(cna@vuldb.com)
https://vuldb.com/?ctiid.341756(cna@vuldb.com)
https://vuldb.com/?id.341756(cna@vuldb.com)
https://vuldb.com/?submit.736511(cna@vuldb.com)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.