Three high-severity vulnerabilities have been disclosed in UTT HiPER 1250GW devices running versions up to 3.2.7-210907-180535, exposing the routers to remote buffer overflow attacks. The flaws, tracked as CVE-2026-7418, CVE-2026-7419, and CVE-2026-7420, affect strcpy handling in the route/goform/NTP, route/goform/formTaskEdit_ap, and route/goform/ConfigAdvideo components respectively. In each case, an attacker can manipulate the Profile argument to trigger memory corruption.
The vulnerabilities are described as remotely exploitable with low attack complexity and low privileges, and public exploit code is already available. All three CVEs carry high impact ratings across confidentiality, integrity, and availability, and are mapped to CWE-119 and CWE-120, indicating improper bounds handling and classic stack-based buffer overflow conditions. The disclosures point to a broad input-validation weakness in the device web management interface that could enable compromise of affected routers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The disclosures stated that public exploit code was available for the three UTT HiPER 1250GW vulnerabilities. The CVE entries also classified the issues under CWE-119 and CWE-120 and assigned high-impact CVSS scores across multiple versions.
On April 29, 2026, CVE-2026-7418, CVE-2026-7419, and CVE-2026-7420 were recorded for UTT HiPER 1250GW devices up to version 3.2.7-210907-180535. The flaws affect strcpy handling in the NTP, formTaskEdit_ap, and ConfigAdvideo components, enabling remotely exploitable buffer overflows via manipulation of the Profile argument.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.