CVE-2026-1162 is a critical buffer overflow vulnerability affecting UTT HiPER 810 1.7.4-141218 firmware, specifically within the strcpy function in /goform/setSysAdm when handling the passwd1 argument. This flaw allows for remote exploitation with no user interaction required, carrying a CVSS score of 9.8 (Critical) due to its potential for complete compromise of confidentiality, integrity, and availability. While exploit code has been published, there is currently no evidence of active exploitation (KEV listed as No), and it lacks official Metasploit or Nuclei modules, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.4-141218CPE matchmatch criteria | cpe:2.3:o:utt:810_firmware:1.7.4-141218:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.