Two high-severity vulnerabilities have been disclosed in UTT HiPER gateway routers, affecting the HiPER 1250GW and HiPER 1200GW product lines. The flaws, tracked as CVE-2026-5566 and CVE-2026-6186, are buffer overflows in the strcpy handling of the /goform/formNatStaticMap component. In both cases, an attacker can manipulate the NatBind argument to trigger the overflow on vulnerable firmware versions, including HiPER 1250GW up to 3.2.7-210907-180535 and HiPER 1200GW up to 2.5.3-170306.
The vulnerabilities are described as remotely exploitable with low attack complexity, and public exploit disclosure has already been noted for both issues, raising the risk of real-world abuse. The CVE records map the flaws to CWE-119 and CWE-120, indicating classic memory-safety failures with potential impact on confidentiality, integrity, and availability. Organizations using affected UTT devices should urgently identify exposed systems, review vendor advisories and referenced technical details, and prioritize remediation or compensating controls for internet-accessible management interfaces.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A separate CVE entry was recorded for a remote buffer overflow in UTT HiPER 1200GW devices up to version 2.5.3-170306. The vulnerability also involves strcpy in /goform/formNatStaticMap through manipulation of the NatBind argument, with public exploit disclosure noted.
A CVE entry was recorded for a remotely exploitable buffer overflow in UTT HiPER 1250GW devices up to version 3.2.7-210907-180535. The flaw affects strcpy handling in /goform/formNatStaticMap via the NatBind argument, and public exploit references were noted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.