520w
Vendor:
First CVE: Dec 6, 2025 · Active for under a year
26
Total CVEs
More Total CVEs than 95% of tracked products
13.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 73% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact 520w over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 6, 2025
7 months ago
Most Recent CVE
Apr 6, 2026
109 days ago
CVE Severity & Scoring
520w26 CVEs
19%
73%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (84.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network4 (15.4%)
Attack Complexity
Low26 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None26 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low21 (80.8%)
High3 (11.5%)
None2 (7.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14141CRITICAL A flaw has been found in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formArpBindConfig. Executing manipulation of the argument pools c | Dec 6, 2025 | 9.8 | 33 | NO | NO |
CVE-2026-1139HIGH A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/ConfigExceptMSN. The manipulation leads to buffer ove | Jan 19, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-1140HIGH A vulnerability was found in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/ConfigExceptAli. The manipulation results in buffer overflow. It i | Jan 19, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-0838HIGH A security flaw has been discovered in UTT 进取 520W 1.7.7-180627. This impacts the function strcpy of the file /goform/ConfigWirelessBase. Performing a manipulation of the argument | Jan 11, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-1138HIGH A flaw has been found in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/ConfigExceptQQ. Executing a manipulation can lead to buffer overflow. The at | Jan 19, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-0841HIGH A vulnerability was detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /goform/formPictureUrl. The manipulation of the argument importp | Jan 11, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-0840HIGH A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this vulnerability is the function strcpy of the file /goform/formConfigNoticeConfig. The manipu | Jan 11, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-0837HIGH A vulnerability was identified in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formFireWall. Such manipulation of the argument GroupName leads to | Jan 11, 2026 | 8.8 | 30 | NO | NO |
CVE-2025-15460HIGH A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formPptpClientConfig. Performing a manipulation of the argument Encry | Jan 5, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-31059CRITICAL A remote command execution (RCE) vulnerability in the /goform/formDia component of UTT Aggressive HiPER 520W v3v1.7.7-180627 allows attackers to execute arbitrary commands via a cr | Apr 6, 2026 | 9.8 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (26 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (26 CVEs).
Media Mentions
Signals from CVEs in this product scope (26 CVEs).
Top CNAs Publishing CVEs For 520w
Top CWEs
Versions
No cataloged versions.