---
id: CVE-2025-15460
title: A vulnerability was detected in UTT 进取 520W 1.7.7-180627
summary: >-
  A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This affects the
  function strcpy of the file /goform/formPptpClientConfig. Performing a
  manipulation of the argument EncryptionMode results in buffer overflow. Remote
  exploitation…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-120
vendor: utt
product: 520w_firmware
affected:
  - 520w_firmware <= 1.7.7-180627
published: '2026-01-05'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15460'
references:
  - url: 'https://github.com/cymiao1978/cve/blob/main/new/23.md'
    label: cna@vuldb.com
  - url: 'https://github.com/cymiao1978/cve/blob/main/new/23.md#poc'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.339496'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.339496'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.725817'
    label: cna@vuldb.com
  - url: 'https://github.com/cymiao1978/cve/blob/main/new/23.md'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00617
epssPercentile: 0.476
ingestedAt: '2026-09-30T23:29:32.530Z'
---

## Overview

A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formPptpClientConfig. Performing a manipulation of the argument EncryptionMode results in buffer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `520w_firmware <= 1.7.7-180627`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
