CVE-2026-2086 is a critical buffer overflow vulnerability affecting UTT HiPER 810G devices running firmware up to version 1.7.7-171114. Specifically, the strcpy function within the /goform/formFireWall component of the management interface is susceptible to manipulation of the GroupName argument. This vulnerability carries a CVSS score of 8.8 (HIGH), indicating a severe risk. It can be exploited remotely with low attack complexity and requires only low privileges, potentially leading to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation in the wild or inclusion in CISA's KEV catalog, a public exploit is available. Despite this, the vulnerability has received minimal community discussion or media coverage, and the vendor has not responded to disclosure attempts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.7-171114CPE matchmatch criteria | cpe:2.3:o:utt:810g_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.