CVE-2026-31063 is a buffer overflow vulnerability discovered in UTT Aggressive HiPER 1200GW v2.5.3-170306 affecting the pools parameter of the formArpBindConfig function. This flaw enables attackers to trigger a Denial of Service condition through specially crafted input. The vulnerability carries a CVSS score of 4.5 (Medium severity) with an adjacent network attack vector, high privilege requirements, and high availability impact. Exploitation of this vulnerability requires an attacker to be on the adjacent network and possess high-level user privileges, which substantially limits the threat landscape. There is currently no evidence of active exploitation, as the vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and maintains an inactive status on threat tracking lists. The extremely low EPSS score of 0.00016 indicates minimal probability of exploitation in the wild, suggesting this remains a low-priority concern for most organizations despite the moderate CVSS rating.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.5.3-170306CPE matchmatch criteria | cpe:2.3:o:utt:1200gw_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.