UTT HiPER 810G Buffer Overflow Vulnerability in formConfigDnsFilterGlobal

Vulnerability

A buffer overflow vulnerability has been identified in the UTT HiPER 810G router, specifically in versions through 1.7.7-171114. The issue arises in the formConfigDnsFilterGlobal function, where the strcpy command is used to copy data without proper size validation. This flaw allows for remote exploitation, leading to potential buffer overflow attacks and denial-of-service conditions.

Impact

Exploitation of this vulnerability causes a buffer overflow, which can lead to arbitrary code execution or a denial-of-service condition.

Reproduction

The vulnerability can be reproduced by sending a POST request to the /goform/formConfigDnsFilterGlobal endpoint. The request must include a 'GroupName' parameter with a value that exceeds the buffer size, bypassing the input validation. This can be done by crafting a request that takes advantage of the vulnerable strcpy function, which improperly handles the input data.

Added: Mar 8, 2026, 3:18 AM
Updated: Mar 8, 2026, 3:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.6
remediation
0.0
relevance
3.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.