Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Utt

First CVE: Jun 16, 2025Active for: 1 yearTotal CVEs: 88
54.9
VTI Score
TOP TARGET

Utt manufactures a focused line of networking and telecommunications equipment, including the 520W, 810G, and 512W device families and their associated firmware, that occupy a prominent role in deployed infrastructure despite a modest product count. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur consistently through memory-safety and command-injection weakness classes—classic buffer overflows, memory-bounds violations, OS command injection, and downstream injection flaws—that are characteristic of embedded systems with native code execution paths. The concentration of critical issues across multiple product lines reflects the inherent risks of firmware-based devices where memory corruption or command manipulation can grant direct system control. Defenders should treat Utt device advisories as high-priority, particularly for internet-facing or management-accessible instances, and inventory affected models for patch deployment. Current exploitation activity, KEV status, and detailed severity counts are shown alongside this summary.

FAUCET AI Generated
88
Total CVEs
More Total CVEs than 99% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
8.4
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Utt over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 16, 2025
13 months ago
Most Recent CVE
Apr 6, 2026
109 days ago

Products(24 total)

Top CVEs

Signals from CVEs in this vendor scope (88 CVEs).

88 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-13442CRITICAL
A security vulnerability has been detected in UTT 进取 750W up to 3.2.2-191225. Affected by this vulnerability is the function system of the file /goform/formPdbUpConfig. Such manipu
Nov 20, 20259.845NONO
CVE-2025-14535CRITICAL
A vulnerability was identified in UTT 进取 512W up to 3.1.7.7-171114. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. The manipulation of the argument s
Dec 11, 20259.834NONO
CVE-2025-14534CRITICAL
A vulnerability was determined in UTT 进取 512W up to 3.1.7.7-171114. This impacts the function strcpy of the file /goform/formNatStaticMap of the component Endpoint. Executing manip
Dec 11, 20259.834NONO
CVE-2025-70998CRITICAL
UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain insecure default credentials for the telnet service, possibly allowing a remote attacker to gain roo
Feb 18, 20269.833NONO
CVE-2025-15092CRITICAL
A vulnerability was identified in UTT 进取 512W up to 1.7.7-171114. Impacted is the function strcpy of the file /goform/ConfigExceptMSN. Such manipulation of the argument remark lead
Dec 26, 20259.833NONO
CVE-2025-15091CRITICAL
A vulnerability was determined in UTT 进取 512W up to 1.7.7-171114. This issue affects the function strcpy of the file /goform/formPictureUrl. This manipulation of the argument impor
Dec 26, 20259.833NONO
CVE-2025-15090CRITICAL
A vulnerability was found in UTT 进取 512W up to 1.7.7-171114. This vulnerability affects the function strcpy of the file /goform/formConfigNoticeConfig. The manipulation of the argu
Dec 25, 20259.833NONO
CVE-2025-15089CRITICAL
A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. This affects the function strcpy of the file /goform/APSecurity. The manipulation of the argument wepkey1 leads to
Dec 25, 20259.833NONO
CVE-2025-14191CRITICAL
A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. Affected by this issue is the function strcpy of the file /goform/formP2PLimitConfig. Such manipulation of the arg
Dec 7, 20259.833NONO
CVE-2025-14141CRITICAL
A flaw has been found in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formArpBindConfig. Executing manipulation of the argument pools c
Dec 6, 20259.833NONO
View all 88 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products88 CVEs
11%
73%
16%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network79 (89.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network9 (10.2%)
Attack Complexity
Low88 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None88 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low57 (64.8%)
High16 (18.2%)
None15 (17.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (88 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Utt.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Utt — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Utt's Products

View all 2 CNAs →

Top CWEs