HIGH 7.5

CVE-2026-52195: UTT nv518G Buffer Overflow Remote DoS Vulnerability

A buffer overflow vulnerability exists in UTT nv518G devices running firmware version nv518GV3v3.2.7-210919-161313. A remote attacker can exploit this flaw in the gohead component to crash the device, causing denial of service. No authentication is required to trigger the vulnerability, and it can be attacked over the network without user interaction.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
CWE-120
Affected products
0 configuration(s)
Published / Modified
2026-06-30 / 2026-07-02

NVD description (verbatim)

Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_472f08 component

3 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-52195 is a CWE-120 classic buffer overflow in the gohead/sub_472f08 component of UTT nv518G firmware. The vulnerability permits an unauthenticated remote attacker to send specially crafted input that overflows a buffer, leading to application crash and service unavailability. The CVSS 3.1 score of 7.5 (HIGH) reflects the network-accessible attack vector, low complexity, and high availability impact, though confidentiality and integrity remain unaffected.

Business impact

Devices running vulnerable firmware versions can be rendered unavailable through remote denial-of-service attacks. For organizations relying on UTT nv518G equipment in production, successful exploitation could disrupt network operations, access, or video surveillance capabilities depending on deployment context. The attack requires no credentials or user interaction, making it a persistent threat until patching is completed.

Affected systems

UTT nv518G devices with firmware version nv518GV3v3.2.7-210919-161313 are confirmed affected. Organizations should audit their hardware inventory to identify instances of this firmware revision. The vulnerability may affect other firmware versions; check the UTT vendor advisory for the full affected version range and any newer versions that address this issue.

Exploitability

Exploitability is straightforward due to the network-accessible, unauthenticated attack surface (CVSS AV:N, PR:N, UI:N). Existing public information about the gohead component and buffer overflow techniques may lower the barrier to weaponization. However, this vulnerability is not currently listed in the CISA KEV catalog, indicating limited evidence of active, widespread exploitation at this time—though absence from KEV does not guarantee lack of threat.

Remediation

The primary remediation is to upgrade affected UTT nv518G devices to a patched firmware version. Consult the UTT security advisory for the specific patched version number and deployment instructions. Until patches are available or applied, consider isolating vulnerable devices from untrusted networks or implementing network-level access controls to restrict who can reach the affected service.

Patch guidance

Contact UTT for official firmware patches addressing CVE-2026-52195. Verify patch version numbers and compatibility with your specific hardware models before deployment. Test patches in a non-production environment to confirm functionality and that they do not introduce regressions. Establish a phased rollout plan for production devices to minimize service disruption.

Detection guidance

Monitor for abnormal restarts or crashes of UTT nv518G devices, particularly if correlated with unusual network traffic. Network-based detection may identify suspicious payloads targeting the gohead service port. Enable logging on affected devices to capture connection attempts and input anomalies. Consider threat-hunting for signs of exploitation if these devices face untrusted network exposure.

Why prioritize this

Although not yet exploited at scale (per KEV status), the combination of HIGH severity, zero authentication requirements, and remote network accessibility makes this a priority for rapid patching. Buffer overflow vulnerabilities in exposed network services pose persistent risk; early remediation limits the window during which attackers can weaponize this flaw.

Risk score, explained

The CVSS 3.1 score of 7.5 reflects a HIGH-severity vulnerability with significant impact potential. The attack vector is network-based, complexity is low, and no privileges or user interaction are needed—all factors that raise risk. The vulnerability achieves high availability impact through denial of service. Confidentiality and integrity are not compromised, preventing a critical rating, but the ease of exploitation and widespread accessibility of affected devices justify close attention.

Frequently asked questions

Is CVE-2026-52195 currently being exploited in the wild?

No, this vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of the latest update. However, KEV listing lags real-world exploitation, and the low attack complexity means exploitation could accelerate once public details become widely known.

Do all UTT nv518G devices have this vulnerability?

Only devices running the specific firmware version nv518GV3v3.2.7-210919-161313 are confirmed vulnerable. Other firmware versions may also be affected; review the official UTT security advisory for the complete list of affected and patched versions.

What can an attacker achieve by exploiting this vulnerability?

An attacker can cause a denial of service by crashing the device. They cannot steal data or gain code execution under normal circumstances. However, repeated crashes could be used to disrupt operations or as a stepping stone in a larger attack if the device serves a critical function.

What steps should we take immediately if we use UTT nv518G devices?

First, identify which devices run the vulnerable firmware version. Second, check the UTT vendor advisory for available patches. Third, plan and test patches in a lab environment. Finally, schedule a phased deployment to production systems, prioritizing devices on untrusted or internet-facing networks.

This analysis is provided for informational purposes to support vulnerability management and security decision-making. SEC.co does not verify vendor product claims or patch availability. Organizations must consult official UTT security advisories and product documentation for authoritative patch version numbers, compatibility information, and deployment guidance. The absence of this vulnerability from the CISA KEV catalog does not guarantee lack of real-world exploitation; organizations should apply standard vulnerability management prioritization based on their own risk assessment and exposure. No exploit code or weaponized proof-of-concept is provided or endorsed herein. Source: NVD (public-domain), retrieved 2026-08-09. Analysis generated by SEC.co (claude-haiku-4-5).