What is CVE-2026-18897?
A stack-based buffer overflow vulnerability was found in the function strcpy within the file /goform/getOneApConfTempEntry of UTT HiPER 1250GW firmware up to version 3.2.7-210907-180535. Remote attackers can exploit this by manipulating the tempName argument to execute arbitrary code. Administrators should restrict access to the management interface until a patch is available.
Azərbaycanca: UTT HiPER 1250GW cihazının 3.2.7-210907-180535 versiyasına qədər olan proqram təminatında /goform/getOneApConfTempEntry faylındakı strcpy funksiyasında stack-based buffer overflow zəifliyi aşkar edilib. tempName arqumentinin manipulyasiyası nəticəsində uzaqdan kod icrası mümkündür. İstehsalçı tərəfindən yeniləmə təqdim olunmayıbsa, cihazın idarəetmə interfeysinə giriş məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: UTT
FAQ2
Which argument must be manipulated to achieve Remote Code Execution (RCE) via the CVE-2026-18897 vulnerability in the UTT HiPER 1250GW device?
Attackers can manipulate the `tempName` argument in the strcpy function within the /goform/getOneApConfTempEntry file to exploit the stack-based buffer overflow vulnerability.
What is the recommended temporary measure to protect the UTT HiPER 1250GW device until the CVE-2026-18897 vulnerability is addressed?
Administrators should restrict access to the device's management interface if a patch has not been provided by the vendor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.