Utt manufactures a focused line of networking and telecommunications equipment, including the 520W, 810G, and 512W device families and their associated firmware, that occupy a prominent role in deployed infrastructure despite a modest product count. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur consistently through memory-safety and command-injection weakness classes—classic buffer overflows, memory-bounds violations, OS command injection, and downstream injection flaws—that are characteristic of embedded systems with native code execution paths. The concentration of critical issues across multiple product lines reflects the inherent risks of firmware-based devices where memory corruption or command manipulation can grant direct system control. Defenders should treat Utt device advisories as high-priority, particularly for internet-facing or management-accessible instances, and inventory affected models for patch deployment. Current exploitation activity, KEV status, and detailed severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Utt over time
Signals from CVEs in this vendor scope (88 CVEs).
88 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13442CRITICAL A security vulnerability has been detected in UTT 进取 750W up to 3.2.2-191225. Affected by this vulnerability is the function system of the file /goform/formPdbUpConfig. Such manipu | Nov 20, 2025 | 9.8 | 45 | NO | NO |
CVE-2025-14535CRITICAL A vulnerability was identified in UTT 进取 512W up to 3.1.7.7-171114. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. The manipulation of the argument s | Dec 11, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-14534CRITICAL A vulnerability was determined in UTT 进取 512W up to 3.1.7.7-171114. This impacts the function strcpy of the file /goform/formNatStaticMap of the component Endpoint. Executing manip | Dec 11, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-70998CRITICAL UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain insecure default credentials for the telnet service, possibly allowing a remote attacker to gain roo | Feb 18, 2026 | 9.8 | 33 | NO | NO |
CVE-2025-15092CRITICAL A vulnerability was identified in UTT 进取 512W up to 1.7.7-171114. Impacted is the function strcpy of the file /goform/ConfigExceptMSN. Such manipulation of the argument remark lead | Dec 26, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-15091CRITICAL A vulnerability was determined in UTT 进取 512W up to 1.7.7-171114. This issue affects the function strcpy of the file /goform/formPictureUrl. This manipulation of the argument impor | Dec 26, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-15090CRITICAL A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This vulnerability affects the function strcpy of the file /goform/formConfigNoticeConfig. The manipulation of the argu | Dec 25, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-15089CRITICAL A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. This affects the function strcpy of the file /goform/APSecurity. The manipulation of the argument wepkey1 leads to | Dec 25, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-14191CRITICAL A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. Affected by this issue is the function strcpy of the file /goform/formP2PLimitConfig. Such manipulation of the arg | Dec 7, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-14141CRITICAL A flaw has been found in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formArpBindConfig. Executing manipulation of the argument pools c | Dec 6, 2025 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (88 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Utt.
Media articles that mention a CVE ID that affects a product developed by Utt — matched by CVE ID, not by vendor name.