CVE-2026-52196
Deferred Deferred - Pending Action

Buffer Overflow in UTT nv518G nv518GV3 Firmware

Vulnerability report for CVE-2026-52196, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-06-30

Last updated on: 2026-07-01

Assigner: MITRE

Description

Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_416f28 component

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-06-30
Last Modified
2026-07-01
Generated
2026-07-21
AI Q&A
2026-07-01
EPSS Evaluated
2026-07-19
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
utt nv518g *
utt nv518gv3v3.2.7-210919-161313 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-120 The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a buffer overflow in the UTT nv518G nv518GV3v3.2.7-210919-161313 device. It occurs in the gohead/sub_416f28 component and can be exploited remotely by an attacker.

Detection Guidance

This vulnerability can be detected by sending a specially crafted HTTP POST request to the vulnerable endpoint that includes an excessively long GroupName parameter. The buffer overflow occurs when the GroupName value is too large.

A proof-of-concept involves an HTTP POST request targeting the /gohead/sub_416f28 component with a long GroupName value to trigger the overflow.

While no exact commands are provided, testing can involve sending HTTP POST requests with large payloads in the GroupName field to observe if the system crashes or behaves unexpectedly.

Impact Analysis

The vulnerability allows a remote attacker to cause a denial of service (DoS) on the affected device, potentially disrupting its normal operation.

Compliance Impact

The vulnerability is a buffer overflow in the UTT nv518G nv518GV3v3.2.7-210919-161313 firmware that allows a remote attacker to cause a denial of service. It does not directly impact confidentiality or integrity, as the CVSS score indicates no impact on confidentiality or integrity (C:N/I:N), only availability (A:H).

Since the vulnerability leads to denial of service without direct data breach or unauthorized data access, its effect on compliance with standards like GDPR or HIPAA is indirect. However, denial of service could disrupt availability of services, which may be relevant under regulations requiring system availability and reliability.

No explicit information is provided about data exposure or privacy violations related to this vulnerability, so specific compliance impacts cannot be confirmed from the provided data.

Mitigation Strategies

Immediate mitigation steps include updating the firmware of the affected device to a version that patches the buffer overflow vulnerability.

Since the vulnerability is triggered by a long GroupName parameter in an HTTP POST request, restricting or filtering unusually large input sizes on this parameter at the network or application level can help reduce risk.

Additionally, monitoring and blocking suspicious HTTP POST requests targeting the /gohead/sub_416f28 endpoint may help prevent exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-52196. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart