CVE-2026-7420Disclosure

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file route/goform/ConfigAdvideo. The manipulation of the argument Profile results in buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Exploit: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-29); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-29: 1Mentions · 2026-04-30: 1Mentions · 2026-07-07: 1Technical Details · 2026-04-29: 1Technical Details · 2026-07-07: 104-2904-3007-07
Signal classification2 categories
Disclosure
266.7%
Exploit
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-291
Disclosure1
2026-04-301
Disclosure1
2026-07-071
Exploit1
Full discourse3 posts
  • YogSotho@YogSoth0
    Exploit

    #UTT HiPER 1250GW Multi-CVE #Exploit Kit ⚠️ INDUSTRIAL ROUTER Authoritative Python toolkit that fingerprints, authenticates against, and abuses eight independently published stack/heap buffer-overflow vulnerabilities in the UTT HiPER 1250GW web-management interface. | CVE | Endpoint | Param | Class | CVSS | | --------------- | --------------------------------- | ------------ | ------ | ---- | | CVE-2026-14721 | `/goform/ConfigWirelessBase_5g` | `ssid` | stack | 9.8 | | CVE-2026-5566 | `/goform/formNatStaticMap` | `NatBind` | heap | 9.8 | | CVE-2026-7419 | `/goform/formTaskEdit_ap` | `Profile` | heap | 8.8 | | CVE-2026-4488 | `/goform/setSysAdm` | `passwd1` | heap | 9.8 | | CVE-2026-9631 | `/goform/formConfigFastDirectionW`| `Profile` | stack | 9.0 | | CVE-2026-7420 | `/goform/ConfigAdvideo` | `Profile` | heap | 8.8 | | CVE-2026-4862 | `/goform/formConfigDnsFilterGlobal`| `GroupName` | heap | 9.8 | | CVE-2026-7418 | `/goform/NTP` | `Profile` | stack | 8.8 | #0days #cybersecurity #cybernews #hacking #RCE #CVE #python #security #antisec #infosec #iot #rourer

    Post summary

    The tweet advertises a Python exploit toolkit targeting eight CVEs on the UTT HiPER 1250GW router, offering detailed vulnerability metadata but no evidence of active exploitation, PoC links, or available patches.

    030133725
    1.9K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for UTT HiPER 1250GW (CVE-2026-7420) https://vuldb.com/vuln/360157

    Post summary

    A new vulnerability (CVE‑2026‑7420) with increased severity has been disclosed for UTT HiPER 1250GW, but no further technical details, PoC, or patch information are provided.

    0101059
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7420 Buffer Overflow in UTT HiPER 1250GW ConfigAdvideo Function via Profile Argument https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7420

    Post summary

    CVE-2026-7420 is a newly disclosed buffer overflow vulnerability affecting the ConfigAdvideo function in UTT HiPER 1250GW, triggered via a profile argument.

    0000038
    4.0K followersView on X

Explore more