PT-2026-47291 · Utt · Hiper 2610G
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
UTT HiPER 2610G versions prior to 3.0.0-171107
Description
A remote buffer overflow can occur due to the use of the
strcpy() function within the /goform/formConfigDnsFilterGlobal file. This issue is triggered by manipulating the GroupName argument. A buffer overflow is a condition where a program writes more data to a memory buffer than it can hold, potentially overwriting adjacent memory.Recommendations
Update to a version later than 3.0.0-171107.
As a temporary workaround, restrict access to the
/goform/formConfigDnsFilterGlobal endpoint or avoid using the GroupName parameter until the update is applied.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hiper 2610G