What is CVE-2026-18898?
A stack-based buffer overflow vulnerability has been discovered in UTT HiPER 1200GW up to version v2.5.3-170306, affecting the `strcpy` function in `/goform/ConfigAdvideo` via the `timestart` argument. This flaw allows for remote exploitation. Users should apply the security update from the vendor.
Azərbaycanca: UTT HiPER 1200GW cihazının v2.5.3-170306-ə qədər versiyalarında `ConfigAdvideo` faylındakı `strcpy` funksiyasında `timestart` arqumenti vasitəsilə stack-based buffer overflow zəifliyi aşkar edilib. Bu, uzaqdan istismara imkan verir. Cihazdan istifadə edənlər üçün istehsalçının təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: UTT
FAQ2
What type of vulnerability was discovered in UTT HiPER 1200GW and which file is exploited?
The vulnerability, tracked as CVE-2026-18898, is a stack-based buffer overflow exploited via the `timestart` argument in the `strcpy` function within the `/goform/ConfigAdvideo` file.
Which versions of UTT HiPER 1200GW are affected by CVE-2026-18898?
The vulnerability affects UTT HiPER 1200GW devices up to version v2.5.3-170306.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.