What is CVE-2026-76004?
A stack-based buffer overflow vulnerability has been identified in UTT HiPER 1250GW firmware up to version 3.2.7-210907-180535, affecting the HTTP Handler component. The issue lies in the `strcpy` function within the `/goform/aspApBasicConfigUrcp` file, triggered by manipulating the `pvid` argument. Users should apply vendor patches when available and restrict network access to the device's management interface to mitigate the risk.
Azərbaycanca: UTT HiPER 1250GW cihazının 3.2.7-210907-180535 versiyasına qədər olan proqram təminatında HTTP Handler komponentində stack-based buffer overflow zəifliyi aşkarlanıb. Bu, `/goform/aspApBasicConfigUrcp` faylındakı `strcpy` funksiyası vasitəsilə `pvid` arqumentinin manipulyasiyasından qaynaqlanır. Cihazın sındırılmaması üçün istehsalçıdan yeniləmə gözlənilməli və ya şəbəkə səviyyəsində giriş məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: UTT
FAQ2
What versions of UTT HiPER 1250GW are affected by CVE-2026-76004?
This vulnerability affects firmware up to version 3.2.7-210907-180535.
How does the exploitation of CVE-2026-76004 occur?
Exploitation occurs by manipulating the `pvid` argument in the `strcpy` function within the `/goform/aspApBasicConfigUrcp` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.