Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2025-15460

HIGH · 8.8 CVSS Gepubliceerd: CWE-119

Beschrijving NL

Er is een kwetsbaarheid gedetecteerd in UTT 进取 520W 1.7.7-180627. Dit heeft invloed op de functie strcpy van het bestand /goform/formPptpClientConfig. Het uitvoeren van een manipulatie van het argument EncryptionMode resulteert in buffer overflow. Exploitatie van de aanval op afstand is mogelijk. De exploit is nu openbaar en kan worden gebruikt. De verkoper werd vroeg gecontacteerd over deze openbaarmaking, maar reageerde op geen enkele manier.

Origineel (Engels) tonen

A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formPptpClientConfig. Performing a manipulation of the argument EncryptionMode results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Vendors

Utt

Affected products

520w Firmware 520w

References