CNNVD-202512-4785 Information

CNNVD ID

CNNVD-202512-4785

CVE-2025-15091

  • CNNVD Published: 2025-12-26

Description (Chinese)

UTT 512W是中国艾泰(UTT)公司的一款无线路由器。 UTT 512W 1.7.7-171114及之前版本存在安全漏洞,该漏洞源于对文件/goform/formPictureUrl中函数strcpy的参数importpictureurl的错误操作,可能导致缓冲区溢出攻击。

Description (English)

UTT 512W is a wireless router of the Chinese company UTT. There is a security loophole in UTT 512W 1.7.7-171114 and earlier versions, which stems from the erroneous operation of the argument for function stcpy in document/goform/formPictureUrl, which could lead to an spill-out attack in the buffer zone.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

艾泰

Published

2025-12-26

Last Modified

2026-02-24

References

https://github.com/cymiao1978/cve/blob/main/new/16.md#poc https://vuldb.com/?id.338420 https://vuldb.com/?submit.708350 https://vuldb.com/?ctiid.338420 https://access.redhat.com/security/cve/cve-2025-15091

Share on: