CVE-2026-52196: UTT nv518G Buffer Overflow Denial-of-Service Vulnerability
A buffer overflow vulnerability in the UTT nv518G device (firmware version nv518GV3v3.2.7-210919-161313) allows attackers to remotely crash the device. An attacker on the network can send specially crafted input to the gohead component without any special privileges or user interaction, causing the device to become unresponsive. This is a denial-of-service issue—attackers cannot steal data or gain control, but they can disrupt service availability.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Weaknesses (CWE)
- CWE-120
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-30 / 2026-07-02
NVD description (verbatim)
Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_416f28 component
3 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-52196 is a classic buffer overflow (CWE-120) in the gohead/sub_416f28 component of UTT nv518G. The vulnerability is network-accessible, requires no authentication or user interaction, and triggers a denial-of-service condition when memory bounds are exceeded. The CVSS 3.1 score of 7.5 reflects the high impact on availability, zero impact on confidentiality and integrity, and the ease of exploitation from the network boundary.
Business impact
Organizations running affected UTT nv518G devices face service disruption risk. Unlike vulnerabilities that lead to data theft or system compromise, this threat manifests as availability loss—devices become unresponsive and require manual restart or intervention. In environments where these devices support critical functions (monitoring, gateway, or access control), DoS could impact productivity or operational continuity.
Affected systems
The vulnerability affects UTT nv518G devices running firmware version nv518GV3v3.2.7-210919-161313. Confirm your device model and firmware version through the device's administration interface or system information page. No vendor product data is currently available in structured vulnerability feeds, so verify your environment against the vendor's advisory and security bulletins.
Exploitability
This vulnerability carries high exploitability. The attack vector is network-based, no credentials are required, no special user interaction is needed, and the attack complexity is low. Any attacker with network access to the device can trigger the denial-of-service condition. However, the vulnerability is not yet listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, so active exploitation in the wild has not been formally documented to date.
Remediation
Firmware updates from UTT addressing this buffer overflow should be prioritized. Contact UTT directly or check their security advisory portal for patches released after the vulnerability publication date (June 30, 2026). In the interim, isolate or restrict network access to affected nv518G devices using firewall rules, ACLs, or network segmentation to limit exposure to untrusted networks.
Patch guidance
Obtain the latest firmware release for UTT nv518G from the vendor's support portal or security advisory page. Verify that the firmware version number is higher than nv518GV3v3.2.7-210919-161313. Test the patch in a non-production environment first to ensure compatibility with your deployment. Once validated, schedule a maintenance window to apply the update, as device restart may be required. Confirm successful patch application by checking the firmware version post-update.
Detection guidance
Monitor network traffic to affected nv518G devices for abnormal or malformed input patterns targeting the gohead component. Implement intrusion detection system (IDS) signatures that detect buffer overflow attempts against this device class. Review device logs for unexpected restarts, crashes, or 'denial-of-service' error conditions. Tools like network packet analyzers (tcpdump, Wireshark) can help capture and inspect suspicious requests if incident investigation is needed.
Why prioritize this
Despite the availability-only impact, the high CVSS score (7.5) reflects unauthenticated network access and ease of exploitation. Organizations with business-critical applications or services relying on these devices should prioritize patching. Conversely, if nv518G devices serve non-critical functions or are already isolated from untrusted networks, remediation can be scheduled in a standard maintenance cycle. The absence of KEV designation means active exploitation has not been observed at scale, reducing urgency slightly.
Risk score, explained
The 7.5 CVSS 3.1 score captures a denial-of-service vulnerability with network-based attack surface and low attack complexity. The high severity reflects maximum availability impact (A:H) but zero confidentiality and integrity impact (C:N, I:N). The unauthenticated, no-user-interaction nature (PR:N, UI:N) elevates the score; however, the impact is limited to availability, preventing a critical or 9.0+ rating.
Frequently asked questions
Is this vulnerability being actively exploited?
No, CVE-2026-52196 is not listed in CISA's Known Exploited Vulnerabilities catalog as of the latest update. Active exploitation in the wild has not been formally documented, though proof-of-concept code may exist in security research communities.
What happens if I don't patch?
Unpatched devices remain vulnerable to remote denial-of-service attacks. An attacker can trigger a crash or hang on the affected nv518G, rendering it unavailable until manual intervention restarts the device. If your device serves a critical function, availability loss could disrupt operations.
Can attackers gain administrative access or steal data via this vulnerability?
No. This is a denial-of-service vulnerability only. The buffer overflow does not grant remote code execution, credential theft, or privilege escalation. The attack impact is limited to taking the device offline.
How do I determine if my nv518G is running the vulnerable firmware?
Log into your device's web administration interface or SSH terminal and check the system information or firmware version display. Compare it against nv518GV3v3.2.7-210919-161313. If your version matches or is older, you are affected. Contact your IT team or device administrator if you cannot access this information.
This analysis is provided for informational purposes and reflects public vulnerability data as of July 2, 2026. Vendor product lists may be incomplete; verify affected devices against official UTT security advisories and your internal asset inventory. Patch version numbers and availability dates should be confirmed directly with UTT before deployment. No guarantee of exploit code accuracy or real-world exploitation prevalence is made. Organizations should conduct their own risk assessments based on device criticality, network exposure, and business context. Source: NVD (public-domain), retrieved 2026-08-09. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2018-25426HIGHWinMTR 0.91 Denial-of-Service Buffer Overflow Vulnerability
- CVE-2018-25432HIGHArm Whois 3.11 Buffer Overflow Allows Local Code Execution
- CVE-2019-25733HIGHNetShareWatcher 1.5.8.0 SEH Buffer Overflow – Local Code Execution
- CVE-2019-25735HIGHAllPlayer 7.4 Buffer Overflow in URL Handling – Local Code Execution Risk
- CVE-2019-25736HIGHLabF nfsAxe 3.7 Buffer Overflow – Local Code Execution
- CVE-2025-26240HIGHJazzCore python-pdfkit 1.0.0 JavaScript Execution & File Exfiltration
- CVE-2026-0138HIGHAndroid LWIS Buffer Overflow Leading to Local Privilege Escalation
- CVE-2026-0146HIGHAndroid Media Codec Out-of-Bounds Write – RCE Risk