CVE-2025-14534 is a critical buffer overflow vulnerability affecting UTT 进取 512W firmware up to version 3.1.7.7-171114. This flaw, located in the strcpy function within the /goform/formNatStaticMap component, can be triggered remotely by manipulating the NatBind argument. With a CVSS score of 9.8 (CRITICAL), it allows for unauthenticated remote attackers to achieve high impact on confidentiality, integrity, and availability. While not yet in CISA's KEV catalog, a public exploit has been disclosed, and community discussion indicates awareness of this easily exploitable vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.7-171114CPE matchmatch criteria | cpe:2.3:o:utt:512w_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.