CVE-2026-14721Disclosure

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

NVD description

A vulnerability has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects an unknown function of the file /goform/ConfigWirelessBase_5g of the component Web Endpoint. The manipulation of the argument ssid leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-07-05); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-05: 2Mentions · 2026-07-07: 1Exploit Tool / Code · 2026-07-07: 1Patch / Workaround · 2026-07-05: 1Technical Details · 2026-07-05: 1Technical Details · 2026-07-07: 107-0507-07
Signal classification3 categories
Disclosure
133.3%
Patch
133.3%
Exploit
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-07-052
Disclosure1Patch1
2026-07-071
Exploit1
Full discourse3 posts
  • YogSotho@YogSoth0
    Exploit

    #UTT HiPER 1250GW Multi-CVE #Exploit Kit ⚠️ INDUSTRIAL ROUTER Authoritative Python toolkit that fingerprints, authenticates against, and abuses eight independently published stack/heap buffer-overflow vulnerabilities in the UTT HiPER 1250GW web-management interface. | CVE | Endpoint | Param | Class | CVSS | | --------------- | --------------------------------- | ------------ | ------ | ---- | | CVE-2026-14721 | `/goform/ConfigWirelessBase_5g` | `ssid` | stack | 9.8 | | CVE-2026-5566 | `/goform/formNatStaticMap` | `NatBind` | heap | 9.8 | | CVE-2026-7419 | `/goform/formTaskEdit_ap` | `Profile` | heap | 8.8 | | CVE-2026-4488 | `/goform/setSysAdm` | `passwd1` | heap | 9.8 | | CVE-2026-9631 | `/goform/formConfigFastDirectionW`| `Profile` | stack | 9.0 | | CVE-2026-7420 | `/goform/ConfigAdvideo` | `Profile` | heap | 8.8 | | CVE-2026-4862 | `/goform/formConfigDnsFilterGlobal`| `GroupName` | heap | 9.8 | | CVE-2026-7418 | `/goform/NTP` | `Profile` | stack | 8.8 | #0days #cybersecurity #cybernews #hacking #RCE #CVE #python #security #antisec #infosec #iot #rourer

    Post summary

    The tweet announces a Python exploit kit that demonstrates exploitation of eight CVEs in the UTT HiPER 1250GW router, providing technical details but no patches or evidence of active attacks.

    030133725
    1.9K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨HIGH - UTT HiPER 1250GW Stack-Based Buffer Overflow (CVE-2026-14721) A vulnerability has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. The manipulation of the ssid argument in the /goform/ConfigWirelessBase_5g endpoint leads to stack-based buffer overflow. The attack can be carried out remotely. The exploit has been disclosed to the public and may be used. 👉Affected: UTT HiPER 1250GW <= 3.2.7-210907-180535 Action: Update to a fixed firmware version as soon as possible.

    Post summary

    UTT HiPER 1250GW devices up to 3.2.7-210907-180535 suffer a stack‑based buffer overflow that can be exploited remotely; vendors advise immediately updating to the patched firmware.

    00000103
    237 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for UTT HiPER 1250GW (CVE-2026-14721) https://vuldb.com/vuln/376308

    Post summary

    A severe vulnerability, CVE-2026-14721, was disclosed for UTT HiPER 1250GW, with a link to the vulnerability database.

    00000135
    2.3K followersView on X

Explore more