CVE-2026-5566Disclosure

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects the function strcpy of the file /goform/formNatStaticMap. Performing a manipulation of the argument NatBind results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 6 mentions (2026-04-05); latest day: 1
  • 9 total mentions across 4 days

Deep dive

Activity timeline9 mentions / 4d
02356Mentions · 2026-04-04: 1Mentions · 2026-04-05: 6Mentions · 2026-04-06: 1Mentions · 2026-07-07: 1PoC Mentioned / Linked · 2026-04-06: 1PoC Mentioned / Linked · 2026-07-07: 1Exploit Tool / Code · 2026-04-06: 1Exploit Tool / Code · 2026-07-07: 1Technical Details · 2026-04-05: 5Technical Details · 2026-04-06: 1Technical Details · 2026-07-07: 104-0404-0504-0607-07
Signal classification3 categories
Disclosure
555.6%
General
222.2%
Exploit
222.2%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-041
General1
2026-04-056
Disclosure5General1
2026-04-061
Exploit1
2026-07-071
Exploit1
Full discourse9 posts
  • YogSotho@YogSoth0
    Exploit

    #UTT HiPER 1250GW Multi-CVE #Exploit Kit ⚠️ INDUSTRIAL ROUTER Authoritative Python toolkit that fingerprints, authenticates against, and abuses eight independently published stack/heap buffer-overflow vulnerabilities in the UTT HiPER 1250GW web-management interface. | CVE | Endpoint | Param | Class | CVSS | | --------------- | --------------------------------- | ------------ | ------ | ---- | | CVE-2026-14721 | `/goform/ConfigWirelessBase_5g` | `ssid` | stack | 9.8 | | CVE-2026-5566 | `/goform/formNatStaticMap` | `NatBind` | heap | 9.8 | | CVE-2026-7419 | `/goform/formTaskEdit_ap` | `Profile` | heap | 8.8 | | CVE-2026-4488 | `/goform/setSysAdm` | `passwd1` | heap | 9.8 | | CVE-2026-9631 | `/goform/formConfigFastDirectionW`| `Profile` | stack | 9.0 | | CVE-2026-7420 | `/goform/ConfigAdvideo` | `Profile` | heap | 8.8 | | CVE-2026-4862 | `/goform/formConfigDnsFilterGlobal`| `GroupName` | heap | 9.8 | | CVE-2026-7418 | `/goform/NTP` | `Profile` | stack | 8.8 | #0days #cybersecurity #cybernews #hacking #RCE #CVE #python #security #antisec #infosec #iot #rourer

    Post summary

    A Python-based exploit kit targeting eight UTT HiPER 1250GW CVEs is presented with detailed endpoint and payload information, but no indication of active exploitation or patch availability.

    030133725
    1.9K followersView on X
  • TheDarkForge@DarkForgeNews
    Exploit

    [CYBERSEC] 𝗨𝗧𝗧 𝗛𝗶𝗣𝗘𝗥 𝟭𝟮𝟱𝟬𝗚𝗪 𝗕𝘂𝗳𝗳𝗲𝗿 𝗢𝘃𝗲𝗿𝗳𝗹𝗼𝘄 𝗘𝗻𝗮𝗯𝗹𝗲𝘀 𝗨𝗻𝗮𝘂𝘁𝗵𝗲𝗻𝘁𝗶𝗰𝗮𝘁𝗲𝗱 𝗥𝗲𝗺𝗼𝘁𝗲 𝗘𝘅𝗽𝗹𝗼𝗶𝘁 CVE-2026-5566 affects UTT HiPER 1250GW firmware through version 3.2.7-210907-180535. A buffer overflow in /goform/formNatStaticMap, triggered by improper strcpy handling of the NatBind argument, allows unauthenticated remote exploitation. http://CIRCL.lu and TheHackerWire have documented the vulnerability, and a public exploit is available. — 𝗧𝗛𝗘 𝗙𝗢𝗥𝗚𝗘'𝗦 𝗪𝗘𝗜𝗚𝗛𝗧 An unauthenticated buffer overflow with a public exploit on network-edge hardware narrows the window between disclosure and active abuse. 𝘚𝘰𝘶𝘳𝘤𝘦𝘴: 𝘊𝘐𝘙𝘊𝘓.𝘭𝘶 | 𝘛𝘩𝘦𝘏𝘢𝘤𝘬𝘦𝘳𝘞𝘪𝘳𝘦

    Post summary

    CVE-2026-5566 is a buffer overflow vulnerability in UTT HiPER 1250GW firmware, with a publicly available exploit but no evidence of current in‑the‑wild exploitation.

    0000044
    21 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5566 - UTT HiPER 1250GW formNatStaticMap strcpy buffer overflow Intel Report: https://ift.tt/8ykATfm

    Post summary

    A new CVE-2026-5566 is reported as a strcpy buffer overflow in UTT HiPER 1250GW, announced with no PoC or exploitation details yet.

    0000046
    281 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-5566 - High A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects the function strcpy of the file /goform/formNatStaticMap. Performing a manipulation of the argument Nat... https://www.thehackerwire.com/vulnerability/CVE-2026-5566/ https://t.co/8BaXvs2NjX

    Post summary

    The post announces a high‑severity buffer‑overflow vulnerability (CVE‑2026‑5566) affecting UTT HiPER 1250GW’s formNatStaticMap component, and links to an external site for further details.

    0000048
    161 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5566 - UTT HiPER 1250GW formNatStaticMap strcpy buffer overflow Intel Report: https://ift.tt/FQb5oYG

    Post summary

    Intel releases a report detailing CVE-2026-5566 as a strcpy buffer overflow in UTT HiPER 1250GW, but no proof of concept, exploit, or patch is provided.

    0000042
    281 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-5566 A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects the function strcpy of the file /goform/formNatStaticMap. Performing a manipula… https://www.cve.org/CVERecord?id=CVE-2026-5566 ----- Traducción: CVE-2026-5566 Se … http://infoflow.cloud`

    Post summary

    The snippet announces CVE-2026-5566 in UTT HiPER 1250GW but lacks any additional detail regarding its exploitation, mitigation, or severity.

    0000032
    63 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5566 A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects the function strcpy of the file /goform/formNatStaticMap. Performing a manipula… https://www.cve.org/CVERecord?id=CVE-2026-5566

    Post summary

    The text reports that CVE-2026-5566 compromises the strcpy function in UTT HiPER 1250GW firmware, affecting versions up to 3.2.7-210907-180535.

    00000304
    56.8K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5566: HIGH] Critical buffer overflow vulnerability detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Exploitation allows remote attacks via manipulation of the argument NatBind in /goform/formN...#cve,CVE-2026-5566,#cybersecurity https://cvefind.com/CVE-2026-5566

    Post summary

    The post announces a critical buffer overflow vulnerability (CVE‑2026‑5566) in UTT HiPER 1250GW, detailing the affected component and exploitation vector, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    0000038
    612 followersView on X
  • VulDB 🛡@vuldb
    General

    There is a new vulnerability with elevated criticality in UTT HiPER 1250GW (CVE-2026-5566) https://vuldb.com/vuln/355336

    Post summary

    A new critical vulnerability (CVE-2026-5566) has been reported for UTT HiPER 1250GW, but only the fact and criticality are provided without detailed technical or remediation information.

    0000096
    2.1K followersView on X

Explore more