Логотип exploitDog
bind:CVE-2026-1137
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-1137

Количество 3

Количество 3

nvd логотип

CVE-2026-1137

18 дней назад

A vulnerability was detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /goform/formWebAuthGlobalConfig. Performing a manipulation results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-6qwc-c44f-q4q8

18 дней назад

A vulnerability was detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /goform/formWebAuthGlobalConfig. Performing a manipulation results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2026-00634

28 дней назад

Уязвимость функции strcpy() микропрограммного обеспечения маршрутизаторов UTT 520W, позволяющая выполнить произвольный код путем отправки специально сформированного POST-запроса

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-1137

A vulnerability was detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /goform/formWebAuthGlobalConfig. Performing a manipulation results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
0%
Низкий
18 дней назад
github логотип
GHSA-6qwc-c44f-q4q8

A vulnerability was detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /goform/formWebAuthGlobalConfig. Performing a manipulation results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 8.8
0%
Низкий
18 дней назад
fstec логотип
BDU:2026-00634

Уязвимость функции strcpy() микропрограммного обеспечения маршрутизаторов UTT 520W, позволяющая выполнить произвольный код путем отправки специально сформированного POST-запроса

CVSS3: 8.8
0%
Низкий
28 дней назад

Уязвимостей на страницу