Two high-severity vulnerabilities have been disclosed in UTT HiPER router products, affecting HiPER 1200GW devices up to version 2.5.3-170306 and HiPER 1250GW devices up to version 3.2.7-210907-180535. The flaws were assigned CVE-2026-4487 and CVE-2026-4488 and are both described as remotely exploitable buffer overflows tied to unsafe use of the strcpy function, with impact spanning confidentiality, integrity, and availability.
CVE-2026-4487 affects the /goform/websHostFilter component on the HiPER 1200GW, while CVE-2026-4488 affects /goform/setSysAdm on the HiPER 1250GW, where manipulation of the GroupName argument can trigger the overflow. The issues are mapped to CWE-119 and CWE-120, and public exploit disclosure has been noted for both, increasing the urgency for organizations using these devices to identify exposed systems and prioritize remediation or compensating controls.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-4488 was received by cna@vuldb.com for a remotely exploitable strcpy buffer overflow in the /goform/setSysAdm component of UTT HiPER 1250GW devices up to version 3.2.7-210907-180535. The flaw involves manipulation of the GroupName argument, and the entry noted public exploit information and high-impact CVSS assessments.
A new CVE entry, CVE-2026-4487, was recorded for a remotely exploitable strcpy buffer overflow in the /goform/websHostFilter component of UTT HiPER 1200GW devices up to version 2.5.3-170306. The entry noted public exploit disclosure and high impact to confidentiality, integrity, and availability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.