VendorsUTT520w_firmware1.7.7-180627
Vulnerabilities

UTT 520w Firmware 1.7.7-180627

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2026-31059
A remote command execution (RCE) vulnerability in the /goform/formDia component of UTT Aggressive HiPER 520W v3v1.7.7-180627 allows attackers to execute arbitrary commands via a crafted string.
Published 2026-04-06 · Modified
9.8EPSS 0.009
CVE-2025-14141
UTT 进取 520W formArpBindConfig strcpy buffer overflow
Published 2025-12-06 · Analyzed
9.8EPSS 0.008
CVE-2026-2067
UTT 进取 520W formTimeGroupConfig strcpy buffer overflow
Published 2026-02-06 · Analyzed
9.0EPSS 0.009
CVE-2026-2068
UTT 进取 520W formSyslogConf strcpy buffer overflow
Published 2026-02-06 · Analyzed
9.0EPSS 0.007
CVE-2026-2066
UTT 进取 520W formIpGroupConfig strcpy buffer overflow
Published 2026-02-06 · Analyzed
9.0EPSS 0.007
CVE-2026-2070
UTT 进取 520W formPolicyRouteConf strcpy buffer overflow
Published 2026-02-06 · Analyzed
9.0EPSS 0.007
CVE-2026-2071
UTT 进取 520W formP2PLimitConfig strcpy buffer overflow
Published 2026-02-07 · Analyzed
9.0EPSS 0.007
CVE-2025-14140
UTT 进取 520W websHostFilter strcpy buffer overflow
Published 2025-12-06 · Analyzed
6.8EPSS 0.006
CVE-2026-31067
A remote command execution (RCE) vulnerability in the /goform/formReleaseConnect component of UTT Aggressive 520W v3v1.7.7-180627 allows attackers to execute arbitrary commands via a crafted string.
Published 2026-04-06 · Analyzed
6.8EPSS 0.005
CVE-2025-14139
UTT 进取 520W formConfigDnsFilterGlobal strcpy buffer overflow
Published 2025-12-06 · Analyzed
5.7EPSS 0.010
CVE-2026-31062
UTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the filename parameter of the formFtpServerDirConfig function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2026-04-06 · Analyzed
4.5EPSS 0.002
CVE-2026-31065
UTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the addCommand parameter of the formConfigCliForEngineerOnly function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2026-04-06 · Analyzed
4.5EPSS 0.002