Skip to main content

Description

A weakness has been identified in UTT 进取 521G 3.1.1-190816. Affected by this issue is the function doSystem of the file /goform/setSysAdm. Executing a manipulation of the argument passwd1 can lead to command injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

Severity

CVSS 4.0 · CNA8.6 HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
CVSS 3.1 · CNA7.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
CVSS 3.0 · CNA7.2 HIGH
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
CVSS 2.0 · CNA8.3 HIGH
AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR
SSVC · CISA-ADP
Exploitationpoc
Automatableno
Technical impacttotal

Affected Products

VendorProductAffected versions
UTT进取 521G
3.1.1-190816

References

5 Links

Record Details

Published
2026-02-08
Last updated
2026-02-23
Assigner (CNA)
VulDB
Credited to
cha0yang (VulDB User)

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.