HIGH
UTT 进取 521G formPdbUpConfig sub_446B18 os command injection
Published Feb 8, 2026
8.6
HIGHCVSS 4.0
EPSS 6.80%
Description
A vulnerability was determined in UTT 进取 521G 3.1.1-190816. The impacted element is the function sub_446B18 of the file /goform/formPdbUpConfig. Executing a manipulation of the argument policyNames can lead to os command injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected products
-
- Version 3.1.1-190816StatusaffectedConstraints-
- Version
AND
- 3.1.1-190816
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (4)
- https://github.com/cha0yang1/UTT521G/blob/main/RCE2.md exploitThird Party Advisory
- https://vuldb.com/?ctiid.344891 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.344891 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.749733 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://github.com/cha0yang1/UTT521G/blob/main/RCE2.md | exploitThird Party Advisory | |
| https://vuldb.com/?ctiid.344891 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.344891 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.749733 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Feb 8, 2026
Updated Feb 23, 2026
Reserved Feb 7, 2026
Link CVE-2026-2188
CISA Vulnrichment
Updated Feb 9, 2026