---
id: CVE-2025-11305
title: A vulnerability has been found in UTT HiPER 840G up to 3.1.1-190328
summary: >-
  A vulnerability has been found in UTT HiPER 840G up to 3.1.1-190328. Affected
  by this issue is the function strcpy of the file /goform/formTaskEdit. The
  manipulation of the argument txtMin2 leads to buffer overflow. Remote
  exploitation o…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-120
vendor: utt
product: 840g_firmware
affected:
  - 840g_firmware <= 3.1.1-190328
published: '2025-10-05'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11305'
references:
  - url: 'https://github.com/maximdevere/CVE2/issues/3'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.327186'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.327186'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.661807'
    label: cna@vuldb.com
  - url: 'https://github.com/maximdevere/CVE2/issues/3'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.0097
epssPercentile: 0.60743
ingestedAt: '2026-10-09T12:53:28.722Z'
---

## Overview

A vulnerability has been found in UTT HiPER 840G up to 3.1.1-190328. Affected by this issue is the function strcpy of the file /goform/formTaskEdit. The manipulation of the argument txtMin2 leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `840g_firmware <= 3.1.1-190328`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
