CVE-2026-9631Exploit

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/formConfigFastDirectionW of the component Web Management Interface. Performing a manipulation of the argument Profile results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is now public and may be used.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-07-07); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-07: 1Mentions · 2026-07-28: 1Exploit Tool / Code · 2026-07-07: 1Patch / Workaround · 2026-07-28: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-28: 107-0707-28
Signal classification2 categories
Exploit
150.0%
Patch
150.0%
Classification over time
DateTotalLabels
2026-07-071
Exploit1
2026-07-281
Patch1
Full discourse2 posts
  • YogSotho@YogSoth0
    Exploit

    #UTT HiPER 1250GW Multi-CVE #Exploit Kit ⚠️ INDUSTRIAL ROUTER Authoritative Python toolkit that fingerprints, authenticates against, and abuses eight independently published stack/heap buffer-overflow vulnerabilities in the UTT HiPER 1250GW web-management interface. | CVE | Endpoint | Param | Class | CVSS | | --------------- | --------------------------------- | ------------ | ------ | ---- | | CVE-2026-14721 | `/goform/ConfigWirelessBase_5g` | `ssid` | stack | 9.8 | | CVE-2026-5566 | `/goform/formNatStaticMap` | `NatBind` | heap | 9.8 | | CVE-2026-7419 | `/goform/formTaskEdit_ap` | `Profile` | heap | 8.8 | | CVE-2026-4488 | `/goform/setSysAdm` | `passwd1` | heap | 9.8 | | CVE-2026-9631 | `/goform/formConfigFastDirectionW`| `Profile` | stack | 9.0 | | CVE-2026-7420 | `/goform/ConfigAdvideo` | `Profile` | heap | 8.8 | | CVE-2026-4862 | `/goform/formConfigDnsFilterGlobal`| `GroupName` | heap | 9.8 | | CVE-2026-7418 | `/goform/NTP` | `Profile` | stack | 8.8 | #0days #cybersecurity #cybernews #hacking #RCE #CVE #python #security #antisec #infosec #iot #rourer

    Post summary

    The post announces an exploit kit that automatically targets eight high‑CVSS buffer‑overflow vulnerabilities in the UTT HiPER 1250GW router, providing a Python toolkit and detailed vulnerability data.

    030133725
    1.9K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH Severity: CVE-2026-9631 (CVSS 8.8) UTT HiPER 1250GW ≤3.2.7 vulnerable to stack-based buffer overflow via Web Management Interface. Exploit is PUBLIC. Remote attack possible with low privileges. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/WPKUZJXXIf

    Post summary

    The tweet alerts to CVE‑2026‑9631, a stack‑based buffer overflow in UTT HiPER 1250GW, and urges immediate patching, noting the exploit is publicly available, but offers no PoC or active exploitation evidence.

    0000050
    97 followersView on X

Explore more