UTT 进取 520W Buffer Overflow Vulnerability in PPTP Client Configuration

Vulnerability

A buffer overflow vulnerability has been identified in the UTT 进取 520W router, specifically in the firmware version through 1.7.7-180627. The issue arises in the 'strcpy' function within the '/goform/formPptpClientConfig' file. By manipulating the 'EncryptionMode' argument, an attacker can exploit this vulnerability remotely, leading to a denial-of-service condition.

Impact

Exploitation of this vulnerability causes a buffer overflow, which can be leveraged to disrupt the normal operation of the device, potentially leading to arbitrary code execution or causing the device to become unresponsive.

Reproduction

The vulnerability can be reproduced by sending a POST request to '/goform/formPptpClientConfig' with a crafted 'EncryptionMode' parameter. The request must include a valid Digest authorization header. This can be done using tools like curl or Postman, or by writing a script to automate the process.

Added: Jan 5, 2026, 6:18 AM
Updated: Jan 5, 2026, 6:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.1
remediation
0.0
relevance
1.9
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.