CVE-2026-4488Disclosure

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected is the function strcpy of the file /goform/setSysAdm. Such manipulation of the argument GroupName leads to buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Exploit: 1 classified signal
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-03-20); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-20: 3Mentions · 2026-03-21: 1Mentions · 2026-03-22: 1Mentions · 2026-07-07: 1PoC Mentioned / Linked · 2026-03-20: 1Technical Details · 2026-03-20: 3Technical Details · 2026-03-22: 1Technical Details · 2026-07-07: 103-2003-2103-2207-07
Signal classification4 categories
Disclosure
350.0%
Exploit
116.7%
General
116.7%
PoC
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-203
Disclosure2Exploit1
2026-03-211
General1
2026-03-221
Disclosure1
2026-07-071
PoC1
Full discourse6 posts
  • YogSotho@YogSoth0
    PoC

    #UTT HiPER 1250GW Multi-CVE #Exploit Kit ⚠️ INDUSTRIAL ROUTER Authoritative Python toolkit that fingerprints, authenticates against, and abuses eight independently published stack/heap buffer-overflow vulnerabilities in the UTT HiPER 1250GW web-management interface. | CVE | Endpoint | Param | Class | CVSS | | --------------- | --------------------------------- | ------------ | ------ | ---- | | CVE-2026-14721 | `/goform/ConfigWirelessBase_5g` | `ssid` | stack | 9.8 | | CVE-2026-5566 | `/goform/formNatStaticMap` | `NatBind` | heap | 9.8 | | CVE-2026-7419 | `/goform/formTaskEdit_ap` | `Profile` | heap | 8.8 | | CVE-2026-4488 | `/goform/setSysAdm` | `passwd1` | heap | 9.8 | | CVE-2026-9631 | `/goform/formConfigFastDirectionW`| `Profile` | stack | 9.0 | | CVE-2026-7420 | `/goform/ConfigAdvideo` | `Profile` | heap | 8.8 | | CVE-2026-4862 | `/goform/formConfigDnsFilterGlobal`| `GroupName` | heap | 9.8 | | CVE-2026-7418 | `/goform/NTP` | `Profile` | stack | 8.8 | #0days #cybersecurity #cybernews #hacking #RCE #CVE #python #security #antisec #infosec #iot #rourer

    Post summary

    The tweet advertises a Python toolkit that exploits eight identified buffer‑overflow vulnerabilities in a UTT HiPER 1250GW router, providing CVE IDs, endpoints, and CVSS scores, but it does not share exploit code or report active attacks.

    030133725
    1.9K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4488 A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected is the function strcpy of the file /goform/setSysAdm. Such manipulation of the ar… https://www.cve.org/CVERecord?id=CVE-2026-4488

    Post summary

    This record announces a vulnerability in UTT HiPER 1250GW firmware where a strcpy function in /goform/setSysAdm is improperly handled, impacting versions up to 3.2.7-210907-180535.

    0000074
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-4488 - UTT - HiPER 1250GW - https://www.redpacketsecurity.com/cve-alert-cve-2026-4488-utt-hiper-1250gw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4488 #utt #hiper-1250gw

    Post summary

    A brief tweet announcing CVE-2026-4488 with a link, but no additional details on the vulnerability or its exploitation are provided.

    0000052
    3.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4488 - High A vulnerability was identified in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected is the function strcpy of the file /goform/setSysAdm. Such manipulation of the argument GroupName leads t... https://www.thehackerwire.com/vulnerability/CVE-2026-4488/ https://t.co/wNndb7mKgN

    Post summary

    The post announces CVE-2026-4488 for UTT HiPER 1250GW, detailing a strcpy overflow involving the GroupName argument, but provides no PoC, patch, or evidence of active exploitation.

    0000046
    138 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4488 - UTT HiPER 1250GW setSysAdm strcpy buffer overflow Intel Report: https://ift.tt/RPLzrt8

    Post summary

    An Intel report has disclosed CVE‑2026‑4488 as a strcpy buffer overflow in UTT HiPER 1250GW's setSysAdm, but no PoC, exploit, patch, or active exploitation details are provided.

    0000037
    334 followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-4488: HIGH] Critical vulnerability in UTT HiPER 1250GW up to 3.2.7-210907-180535 allows remote attackers to trigger a buffer overflow via manipulated arguments. Public exploit available. #CyberSecurity#cve,CVE-2026-4488,#cybersecurity https://cvefind.com/CVE-2026-4488

    Post summary

    The text announces a high‑severity CVE‑2026‑4488 in UTT HiPER 1250GW, detailing a buffer overflow and noting that a public exploit is available.

    0000065
    604 followersView on X

Explore more