CVE-2025-15431 describes a buffer overflow vulnerability in UTT 进取 512W 1.7.7-171114, specifically within the strcpy function of /goform/formFtpServerDirConfig when processing the 'filename' argument. This flaw, affecting utt 512w and its firmware, allows for remote exploitation with low attack complexity and no user interaction required. With a CVSS score of 8.8 (HIGH), successful exploitation can lead to high impact on confidentiality, integrity, and availability. An exploit has been publicly disclosed, though it is not currently listed in Metasploit, Nuclei, or ExploitDB, and there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.7-171114CPE matchmatch criteria | cpe:2.3:o:utt:512w_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.