---
id: CVE-2025-11652
title: A vulnerability was found in UTT 进取 518G up to V3v3.2.7-210919-161313
summary: >-
  A vulnerability was found in UTT 进取 518G up to V3v3.2.7-210919-161313. This
  issue affects some unknown processing of the file /goform/formTaskEdit_ap. The
  manipulation of the argument txtMin2 results in buffer overflow. The attack
  may be…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-120
vendor: utt
product: 518g_firmware
affected:
  - 518g_firmware <= 3.2.7-210919-161313
published: '2025-10-13'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11652'
references:
  - url: 'https://github.com/cymiao1978/cve/blob/main/14.md'
    label: cna@vuldb.com
  - url: 'https://github.com/cymiao1978/cve/blob/main/14.md#poc'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.328069'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.328069'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.664926'
    label: cna@vuldb.com
  - url: 'https://github.com/cymiao1978/cve/blob/main/14.md'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://github.com/cymiao1978/cve/blob/main/14.md#poc'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00838
epssPercentile: 0.56471
ingestedAt: '2026-10-08T12:39:48.698Z'
---

## Overview

A vulnerability was found in UTT 进取 518G up to V3v3.2.7-210919-161313. This issue affects some unknown processing of the file /goform/formTaskEdit_ap. The manipulation of the argument txtMin2 results in buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `518g_firmware <= 3.2.7-210919-161313`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
