CVE-2026-2847

A vulnerability was detected in UTT HiPER 520 1.7.7-160105. Affected is the function sub_44EFB4 of the file /goform/formReleaseConnect of the component Web Management Interface. The manipulation of the argument Isp_Name results in os command injection. The attack can be launched remotely. The exploit is now public and may be used.
References
Link Resource
https://github.com/cha0yang1/UTT520CVE/blob/main/UTTRCE2.md Exploit Third Party Advisory
https://vuldb.com/?ctiid.347083 Permissions Required VDB Entry
https://vuldb.com/?id.347083 Third Party Advisory VDB Entry
https://vuldb.com/?submit.753965 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:utt:520_firmware:1.7.7-160105:*:*:*:*:*:*:*
cpe:2.3:h:utt:520:3.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-20 16:22

Updated : 2026-02-24 15:25


NVD link : CVE-2026-2847

Mitre link : CVE-2026-2847

CVE.ORG link : CVE-2026-2847


JSON object : View

Products Affected

utt

  • 520
  • 520_firmware
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')