CVE-2025-15090

HIGH

UTT 512w Firmware < 1.7.7-171114 - Memory Corruption

Title source: rule
STIX 2.1

Description

A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This vulnerability affects the function strcpy of the file /goform/formConfigNoticeConfig. The manipulation of the argument timestart results in buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.

Scores

CVSS v3 8.8
EPSS 0.0021
EPSS Percentile 42.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-119 CWE-120
Status published
Products (1)
utt/512w_firmware < 1.7.7-171114
Published Dec 25, 2025
Tracked Since Feb 18, 2026