HIGH
UTT 进取 520W formConfigNoticeConfig strcpy buffer overflow
Published Jan 11, 2026
8.7
HIGHCVSS 4.0
EPSS 4.08%
Description
A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this vulnerability is the function strcpy of the file /goform/formConfigNoticeConfig. The manipulation of the argument timestart leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
- Version 1.7.7-180627StatusaffectedConstraints-
- Version
AND
- ≤ 1.7.7-180627
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-1903 Advisory
- https://github.com/GUOTINGTING2297/cve/blob/main/1234/30.md exploitThird Party Advisory
- https://vuldb.com/?ctiid.340440 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.340440 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.729029 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-1903 | Advisory | |
| https://github.com/GUOTINGTING2297/cve/blob/main/1234/30.md | exploitThird Party Advisory | |
| https://vuldb.com/?ctiid.340440 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.340440 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.729029 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Jan 11, 2026
Updated Feb 23, 2026
Reserved Jan 10, 2026
Link CVE-2026-0840
CISA Vulnrichment
Updated Jan 12, 2026
ENISA EUVD
EUVD-2026-1903 Assigner VulDB
Published Jan 11, 2026
Updated Feb 23, 2026
Exploited since n/a
Link EUVD-2026-1903