---
id: CVE-2025-11323
title: A vulnerability was determined in UTT 1250GW up to v2v3.2.2-200710
summary: >-
  A vulnerability was determined in UTT 1250GW up to v2v3.2.2-200710. Affected
  is the function strcpy of the file /goform/formUserStatusRemark. This
  manipulation of the argument Username causes buffer overflow. Remote
  exploitation of the a…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-120
vendor: utt
product: 1250gw_firmware
affected:
  - 1250gw_firmware <= 3.2.2-200710
published: '2025-10-06'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11323'
references:
  - url: 'https://github.com/DavCloudz/cve/issues/3'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.327206'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.327206'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.664524'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00752
epssPercentile: 0.53621
ingestedAt: '2026-10-09T12:53:28.752Z'
---

## Overview

A vulnerability was determined in UTT 1250GW up to v2v3.2.2-200710. Affected is the function strcpy of the file /goform/formUserStatusRemark. This manipulation of the argument Username causes buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `1250gw_firmware <= 3.2.2-200710`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
