CVE-2026-2118 describes a critical command injection vulnerability in the UTT HiPER 810 1.7.4-141218 router firmware, specifically within the rehttpd component's sub_4407D4 function when processing the Isp_Name argument. This flaw allows a highly privileged remote attacker to execute arbitrary commands on the device. Rated 7.2 HIGH on the CVSS scale, this vulnerability carries a significant risk due to its remote attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. The exploit has been publicly disclosed, indicating readily available attack methods. Despite public disclosure of the exploit, there is no evidence of active exploitation (not in KEV or Hot List), nor are there Metasploit or Nuclei modules. Community discussion and media coverage for this CVE are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.4-141218CPE matchmatch criteria | cpe:2.3:o:utt:810_firmware:1.7.4-141218:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.