---
id: CVE-2025-14535
title: A vulnerability was identified in UTT 进取 512W up to 3.1.7.7-171114
summary: >-
  A vulnerability was identified in UTT 进取 512W up to 3.1.7.7-171114. Affected
  is the function strcpy of the file /goform/formConfigFastDirectionW. The
  manipulation of the argument ssid leads to buffer overflow. The attack may be
  initiated…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-120
vendor: utt
product: 512w_firmware
affected:
  - 512w_firmware <= 1.7.7-171114
published: '2025-12-11'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14535'
references:
  - url: 'https://github.com/maximdevere/CVE2/issues/7'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.335874'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.335874'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.703621'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.0563
epssPercentile: 0.92729
ingestedAt: '2026-10-07T20:46:46.860Z'
---

## Overview

A vulnerability was identified in UTT 进取 512W up to 3.1.7.7-171114. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. The manipulation of the argument ssid leads to buffer overflow. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `512w_firmware <= 1.7.7-171114`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
