What is CVE-2026-18895?
A stack-based buffer overflow vulnerability in the `strcpy` function of `/goform/APSecurity_5g` on UTT HiPER 1250GW devices up to version 3.2.7-210907-180535 allows remote attacks via the `cipher` argument. Users should update their firmware or restrict access with firewalls.
Azərbaycanca: UTT HiPER 1250GW cihazlarının 3.2.7-210907-180535 versiyasına qədər olan proqram təminatında, `/goform/APSecurity_5g` faylındakı `strcpy` funksiyasında stack-based buffer overflow zəifliyi aşkar edilib. Bu, uzaqdan hücuma imkan verir; bu modelin istifadəçiləri cihazlarını ən son versiyaya yeniləməli və ya təhlükəsizlik duvarı ilə girişi məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: UTT
FAQ2
Which firmware version of UTT HiPER 1250GW is affected by CVE-2026-18895?
All firmware versions up to 3.2.7-210907-180535 are affected by this stack-based buffer overflow vulnerability.
How can I mitigate the CVE-2026-18895 vulnerability?
You should update the device firmware to the latest version or restrict access with firewalls.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.