CVE-2026-4488

HIGH

UTT HiPER 1250GW setSysAdm strcpy buffer overflow

Title source: cna

Description

A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected is the function strcpy of the file /goform/setSysAdm. Such manipulation of the argument GroupName leads to buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

Scores

CVSS v3 8.8
EPSS 0.0004
EPSS Percentile 12.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119 CWE-120
Status published
Products (1)
UTT/HiPER 1250GW < 3.2.7-210907-180535
Published Mar 20, 2026
Tracked Since Mar 20, 2026