UTT 进取 520W Buffer Overflow Vulnerability in ConfigExceptMSN Function

Vulnerability

A buffer overflow vulnerability has been identified in the UTT 进取 520W router, specifically in the firmware version 1.7.7-180627. The issue arises in the ConfigExceptMSN function, where the strcpy function is used to copy data without proper size validation, allowing for remote exploitation. This vulnerability has been publicly disclosed and could be used to execute a denial-of-service attack.

Impact

Exploitation of this vulnerability leads to a buffer overflow, which can commonly be used to execute arbitrary code or cause a denial-of-service condition by crashing the device.

Reproduction

The vulnerability can be reproduced by sending a POST request to the /goform/ConfigExceptMSN endpoint. The request must include a payload that exceeds the buffer size, effectively causing the overflow. This can be done by manipulating the 'remark' parameter to include a large amount of data.

Added: Jan 19, 2026, 5:19 AM
Updated: Jan 19, 2026, 5:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.4
remediation
0.0
relevance
2.2
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.