


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipul…
Published:
4 augustus 2026 om 22:00:00
Alert date:
5 augustus 2026 om 03:00:59
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT, Zero-Day Vulnerabilities
A stack-based buffer overflow vulnerability has been identified in UTT HiPER 1250GW devices running firmware up to version 3.2.7-210907-180535. The vulnerability exists in the strcpy function within the /goform/APSecurity_5g file, where manipulation of the 'cipher' argument can trigger a buffer overflow. The flaw can be exploited remotely without requiring physical access to the device. A public exploit has been released, increasing the risk of active exploitation. The vulnerability affects the 5GHz wireless security configuration interface of the router. The vendor was contacted prior to public disclosure but did not respond. No patch or mitigation has been confirmed from the vendor at the time of disclosure. This is classified as a high-severity issue given remote exploitability and public exploit availability.
Technical details
Mitigation steps:
Affected products:
UTT HiPER 1250GW up to 3.2.7-210907-180535
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18895
https://github.com/7wkajk/CVE-VUL/blob/main/101.md
https://vuldb.com/cve/CVE-2026-18895
https://vuldb.com/submit/858607
https://vuldb.com/vuln/385930
https://vuldb.com/vuln/385930/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
