HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-18897 — A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. T...

·Source: NIST NVD

Updated:

Executive Summary

A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulation of the argument tempName leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did no

Analysis

A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulation of the argument tempName leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSS Score: 8.8. Published: 2026-08-05T02:16:37.773.

Indicators of Compromise (1)

CVE (1)
CVE-2026-18897
Source Attribution

Originally published by NIST NVD on Aug 5, 2026. Verified by: NIST.

Related Threats

HIGHVulnerability

NVD HIGH: CVE-2026-18898 — A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. Thi...

A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument timestart results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did n

CVE-2026-18898
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-18895 — A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacte...

A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the argument cipher results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respon

CVE-2026-18895
NIST NVD
CRITICALVulnerability

Ruby on Rails critical bug puts every image upload under scrutiny

A new critical vulnerability in the Ruby on Rails (“Rails”) web application framework, CVE-2026-66066 , could turn a seemingly innocuous image into a front door to your secrets. Disclosed July 30, the high severity CVE (scored 9.5 out of 10) poses a significant risk to enterprises running apps that handle user-uploaded images in Rails. Dubbed “KindaRails2Shell,” it targets the overly-trusting Acti

CVE-2026-66066
CSO Online