A vulnerability was determined in UTT 进取 512W up to 1.7.7-171114. This issue affects the function strcpy of the file /goform/formPictureUrl. This manipulation of the argument importpictureurl causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
UTT 进取 512W formPictureUrl strcpy buffer overflow
Problem type
Affected products
UTT
1.7.7-171114 - AFFECTED
References
https://vuldb.com/?id.338420
https://vuldb.com/?ctiid.338420
https://vuldb.com/?submit.708350
https://github.com/cymiao1978/cve/blob/main/new/16.md
https://github.com/cymiao1978/cve/blob/main/new/16.md#poc
GitHub Security Advisories
GHSA-ff49-f5c2-ggcq
A vulnerability was determined in UTT 进取 512W up to 1.7.7-171114. This issue affects the function...
https://github.com/advisories/GHSA-ff49-f5c2-ggcqA vulnerability was determined in UTT 进取 512W up to 1.7.7-171114. This issue affects the function strcpy of the file /goform/formPictureUrl. This manipulation of the argument importpictureurl causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
https://nvd.nist.gov/vuln/detail/CVE-2025-15091
https://github.com/cymiao1978/cve/blob/main/new/16.md
https://github.com/cymiao1978/cve/blob/main/new/16.md#poc
https://vuldb.com/?ctiid.338420
https://vuldb.com/?id.338420
https://vuldb.com/?submit.708350
https://github.com/advisories/GHSA-ff49-f5c2-ggcq
JSON source
https://cveawg.mitre.org/api/cve/CVE-2025-15091Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2025-15091",
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"dateUpdated": "2025-12-26T15:07:08.514Z",
"dateReserved": "2025-12-25T12:42:31.304Z",
"datePublished": "2025-12-25T23:32:06.493Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB",
"dateUpdated": "2025-12-25T23:32:06.493Z"
},
"title": "UTT 进取 512W formPictureUrl strcpy buffer overflow",
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in UTT 进取 512W up to 1.7.7-171114. This issue affects the function strcpy of the file /goform/formPictureUrl. This manipulation of the argument importpictureurl causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized."
}
],
"affected": [
{
"vendor": "UTT",
"product": "进取 512W",
"versions": [
{
"version": "1.7.7-171114",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "Buffer Overflow",
"cweId": "CWE-120",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"lang": "en",
"description": "Memory Corruption",
"cweId": "CWE-119",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://vuldb.com/?id.338420",
"name": "VDB-338420 | UTT 进取 512W formPictureUrl strcpy buffer overflow",
"tags": [
"vdb-entry",
"technical-description"
]
},
{
"url": "https://vuldb.com/?ctiid.338420",
"name": "VDB-338420 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
]
},
{
"url": "https://vuldb.com/?submit.708350",
"name": "Submit #708350 | UTT 进取 512W v3v1.7.7-171114 Buffer Overflow",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://github.com/cymiao1978/cve/blob/main/new/16.md",
"tags": [
"related"
]
},
{
"url": "https://github.com/cymiao1978/cve/blob/main/new/16.md#poc",
"tags": [
"exploit"
]
}
],
"metrics": [
{},
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R",
"baseScore": 8.8,
"baseSeverity": "HIGH"
}
},
{
"cvssV3_0": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R",
"baseScore": 8.8,
"baseSeverity": "HIGH"
}
},
{
"cvssV2_0": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR",
"baseScore": 9
}
}
],
"timeline": [
{
"time": "2025-12-25T00:00:00.000Z",
"lang": "en",
"value": "Advisory disclosed"
},
{
"time": "2025-12-25T01:00:00.000Z",
"lang": "en",
"value": "VulDB entry created"
},
{
"time": "2025-12-25T13:47:42.000Z",
"lang": "en",
"value": "VulDB entry last update"
}
],
"credits": [
{
"lang": "en",
"value": "cymiao (VulDB User)",
"type": "reporter"
}
]
},
"adp": [
{
"providerMetadata": {
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP",
"dateUpdated": "2025-12-26T15:07:08.514Z"
},
"title": "CISA ADP Vulnrichment",
"references": [
{
"url": "https://github.com/cymiao1978/cve/blob/main/new/16.md#poc",
"tags": [
"exploit"
]
}
],
"metrics": [
{}
]
}
]
}
}