CVE-2025-15091

HIGH

UTT 512w Firmware < 1.7.7-171114 - Memory Corruption

Title source: rule
STIX 2.1

Description

A vulnerability was determined in UTT 进取 512W up to 1.7.7-171114. This issue affects the function strcpy of the file /goform/formPictureUrl. This manipulation of the argument importpictureurl causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

Scores

CVSS v3 8.8
EPSS 0.0007
EPSS Percentile 20.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-119 CWE-120
Status published
Products (1)
utt/512w_firmware < 1.7.7-171114
Published Dec 26, 2025
Tracked Since Feb 18, 2026