MEDIUM
UTT HiPER 810 formPdbUpConfig sub_43F020 command injection
Published Feb 8, 2026
5.3
MEDIUMCVSS 4.0
EPSS 4.49%
Description
A vulnerability was detected in UTT HiPER 810 1.7.4-141218. The impacted element is the function sub_43F020 of the file /goform/formPdbUpConfig. Performing a manipulation of the argument policyNames results in command injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Affected products
-
- Version 1.7.4-141218StatusaffectedConstraints-
- Version
AND
- 1.7.4-141218
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://github.com/cha0yang1/UTT810CVE/blob/main/CVEreadme2.md exploitThird Party Advisory
- https://vuldb.com/?ctiid.344770 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.344770 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.747222 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://github.com/cha0yang1/UTT810CVE/blob/main/CVEreadme2.md | exploitThird Party Advisory | |
| https://vuldb.com/?ctiid.344770 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.344770 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.747222 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Feb 8, 2026
Updated Feb 23, 2026
Reserved Feb 6, 2026
Link CVE-2026-2135
CISA Vulnrichment
Updated Feb 10, 2026