Vulnerabilidad · Publicado 19/08/2026
Se ha identificado una vulnerabilidad de desbordamiento de búfer en la pila (stack-based buffer overflow) en UTT HiPER 1250GW versiones hasta 3.2.7-210907-180535. El fallo existe en el manejador HTTP del formulario /goform/aspApBasicConfigUrcp y puede ser explotado remotialmente sin autenticación manipulando el parámetro pvid. El exploit está públicamente disponible, poniendo en riesgo crítico los equipos desplegados en infraestructuras de ISPs, centros de datos y operadores de telecomunicaciones en América Latina.
A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/aspApBasicConfigUrcp of the component HTTP Handler. The manipulation of the argument pvid leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
Score: 9.9/10 — Severidad: CRITICAL — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CWE-119, CWE-121
Publicado en NIST NVD.