UTT vulnerabilities
6 CVEs tracked
UTT networking devices, specifically the HiPER 1200GW (up to v2.5.3-170306) and HiPER 1250GW (up to v3.2.7-210907-180535) models, are featured in recent reports with multiple critical vulnerabilities. All identified flaws are remotely exploitable stack-based buffer overflows caused by improper use of the `strcpy` function in various `/goform/` scripts. The associated CVEs (CVE-2026-18895, CVE-2026-18897, CVE-2026-18898, CVE-2026-19341, CVE-2026-76003, CVE-2026-76004) indicate that defenders must ensure the management interfaces of these devices are not exposed to the internet. Immediately applying firmware updates or implementing access control lists (ACLs) to prevent exposing these affected components is strongly recommended.
Azərbaycanca: UTT şəbəkə avadanlıqları, xüsusilə HiPER 1200GW (v2.5.3-170306-dək) və HiPER 1250GW (v3.2.7-210907-180535-dək) modelləri, son hesabatlarda çoxsaylı kritik boşluqlarla qeyd edilir. Bütün aşkarlanan zəifliklər müxtəlif /goform/ skriptlərində `strcpy` funksiyasının düzgün istifadə edilməməsi nəticəsində yaranan uzaqdan istismar edilə bilən stack-based buffer overflow problemidir. Əsas CVE-lər (CVE-2026-18895, CVE-2026-18897, CVE-2026-18898, CVE-2026-19341, CVE-2026-76003, CVE-2026-76004) şəbəkə müdafiəçilərinin bu cihazların idarəetmə interfeyslərinə internetə açıq olmamasını təmin etməli olduğunu göstərir. Təcili olaraq firmware yeniləmələrini tətbiq etmək və ya bu cihazların məruz qalmış tərkibli hala salınmaması üçün giriş nəzarət siyahıları (ACLs) tətbiq etmək tövsiyə olunur.
This vendor's CVEs6
This hub is built from skopnix's own reporting on UTT: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.