UTT HiPER 2620G Buffer Overflow Vulnerability in NTP Server IP Handling

Vulnerability

A critical buffer overflow vulnerability has been identified in the UTT HiPER 2620G router, affecting firmware versions through 3.1.4. The issue arises in the '/goform/fNTP' endpoint, where the 'NTPServerIP' parameter is manipulated, leading to a buffer overflow via the 'strcpy' function. This vulnerability can be exploited remotely, potentially causing denial-of-service conditions and allowing arbitrary code execution.

Impact

Exploitation of this vulnerability causes a buffer overflow, which can lead to arbitrary code execution on the affected device.

Reproduction

To reproduce this vulnerability, send a POST request to '/goform/fNTP' with the 'NTPServerIP' parameter containing a payload that exceeds the buffer's capacity. The 'SntpEnable' parameter must be set to 'on', and the 'NTPServerIP' must not be empty. This can be done using a web browser or a tool like curl, ensuring that the request includes the necessary headers for authentication.

Added: Oct 13, 2025, 1:20 AM
Updated: Oct 13, 2025, 1:20 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.1
remediation
0.0
relevance
0.7
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.