HIGH
UTT 进取 521G setSysAdm doSystem command injection
Published Feb 8, 2026
8.6
HIGHCVSS 4.0
EPSS 9.74%
Description
A weakness has been identified in UTT 进取 521G 3.1.1-190816. Affected by this issue is the function doSystem of the file /goform/setSysAdm. Executing a manipulation of the argument passwd1 can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected products
-
- Version 3.1.1-190816StatusaffectedConstraints-
- Version
AND
- 3.1.1-190816
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-5768 Advisory
- https://github.com/cha0yang1/UTT521G/blob/main/RCE1.md relatedExploitThird Party Advisory
- https://github.com/cha0yang1/UTT521G/blob/main/RCE1.md#poc exploit
- https://vuldb.com/?ctiid.344885 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.344885 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.749712 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-5768 | Advisory | |
| https://github.com/cha0yang1/UTT521G/blob/main/RCE1.md | relatedExploitThird Party Advisory | |
| https://github.com/cha0yang1/UTT521G/blob/main/RCE1.md#poc | exploit | |
| https://vuldb.com/?ctiid.344885 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.344885 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.749712 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Feb 8, 2026
Updated Feb 23, 2026
Reserved Feb 7, 2026
Link CVE-2026-2182
CISA Vulnrichment
Updated Feb 9, 2026
ENISA EUVD
EUVD-2026-5768 Assigner VulDB
Published Feb 8, 2026
Updated Feb 23, 2026
Exploited since n/a
Link EUVD-2026-5768