CVE-2026-31059

CRITICAL

UTT Aggressive HiPER 520W Firmware - formDia OS Command Injection

Title source: manual
STIX 2.1

Description

A remote command execution (RCE) vulnerability in the /goform/formDia component of UTT Aggressive HiPER 520W v3v1.7.7-180627 allows attackers to execute arbitrary commands via a crafted string.

Scores

CVSS v3 9.8
EPSS 0.0090
EPSS Percentile 54.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-77
Status published
Products (1)
utt/520w_firmware 1.7.7-180627
Published Apr 06, 2026
Tracked Since Apr 06, 2026