HIGH 7.5

CVE-2026-52197: UTT nv518G Denial-of-Service Vulnerability in gohead Component

A vulnerability in UTT nv518G firmware version 3.2.7-210919-161313 allows attackers on the network to crash or disable the device by sending specially crafted requests to the gohead web component. No authentication is required, and the attack can be performed remotely. This is a denial-of-service flaw that could interrupt service availability for organizations relying on this equipment.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
CWE-400
Affected products
0 configuration(s)
Published / Modified
2026-06-30 / 2026-07-02

NVD description (verbatim)

An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_44af70 component

3 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-52197 is a denial-of-service vulnerability affecting UTT nv518G nv518GV3v3.2.7-210919-161313. The flaw resides in the gohead/sub_44af70 component, which handles HTTP requests. An unauthenticated remote attacker can trigger uncontrolled resource consumption (CWE-400) by sending malformed or excessive requests, exhausting system resources and rendering the device unavailable. The vulnerability requires only network connectivity and does not demand user interaction or elevated privileges. The CVSS 3.1 score of 7.5 (HIGH) reflects the network-based attack vector, low complexity, and high impact to availability.

Business impact

Organizations using affected UTT nv518G devices in production environments face risk of service interruption. Since no authentication is required and exploitation is straightforward, any external attacker can disrupt connectivity or functionality of dependent systems. For businesses relying on this hardware for critical network operations, emergency response and device recovery could consume significant operational overhead. The lack of KEV designation does not indicate low severity; rather, widespread exploitation may not yet be documented in public exploit repositories.

Affected systems

The vulnerability specifically affects UTT nv518G nv518GV3 running firmware version 3.2.7-210919-161313. Organizations should inventory devices running this exact firmware version. Verify your device model and build date against the provided version string to confirm exposure. Devices on different firmware versions or alternative UTT models require vendor confirmation of scope before assuming protection.

Exploitability

Exploitation is straightforward: an attacker positioned on the network or internet can craft HTTP requests targeting the vulnerable gohead component without credentials, user interaction, or advanced capabilities. The low complexity and absence of preconditions mean this vulnerability is likely to be actively exploited once public details are disclosed or proof-of-concept code emerges. The HIGH CVSS score accurately reflects this accessibility and the guaranteed availability impact.

Remediation

Contact UTT technical support to obtain a firmware update addressing the gohead component flaw. Verify the patched version number against the vendor's security advisory before deployment. As an interim measure, restrict network access to the device's web interface using firewall rules or network segmentation, allowing only trusted management traffic. If the device is internet-facing, temporarily disable or restrict HTTP/HTTPS access until patching is feasible.

Patch guidance

Verify the latest firmware version available from UTT for the nv518G nv518GV3 line through the vendor's official advisory or support portal. Test the patched firmware in a non-production environment before rollout. Confirm that the new version resolves the gohead/sub_44af70 issue and does not introduce regressions. Document the original firmware version (3.2.7-210919-161313) in your change log and establish a post-patch verification process to confirm availability restoration.

Detection guidance

Monitor network logs and device metrics for unusual HTTP request patterns targeting the gohead component—specifically, high volumes of malformed requests, incomplete HTTP headers, or requests with extreme payload sizes. Watch for device CPU or memory spikes correlating with unusual traffic. Implement network-based intrusion detection rules to flag requests to the vulnerable path if the vendor or security community publishes signatures. Enable device logging at maximum verbosity if supported, and archive logs for forensic analysis if an outage occurs.

Why prioritize this

This vulnerability merits urgent attention despite the absence of KEV status. The combination of unauthenticated remote access, ease of exploitation, and guaranteed denial-of-service impact poses immediate risk. Any organization operating this exact firmware version should prioritize patching or mitigation within days, not weeks. The simplicity of attack execution means widespread exploitation is probable once exploit details circulate in underground forums or security tool repositories.

Risk score, explained

The CVSS 3.1 score of 7.5 (HIGH) is justified by a network-adjacent attack vector (AV:N), low attack complexity (AC:L), no privilege requirements (PR:N), and no user interaction (UI:N). Availability impact is high (A:H), while confidentiality and integrity remain unaffected. This scoring correctly prioritizes the flaw as a significant availability risk suitable for rapid remediation in most operational contexts.

Frequently asked questions

Is this vulnerability being actively exploited in the wild?

As of the publication date, there is no documented evidence of active exploitation in KEV or other threat intelligence feeds. However, the simplicity of exploitation and lack of authentication requirements make widespread attacks likely once public details or proof-of-concept code become available. Assume this will be a target for opportunistic attackers and botnet operators.

Which UTT devices are affected?

Only UTT nv518G nv518GV3 running firmware version 3.2.7-210919-161313 is confirmed in the CVE description. Other UTT models or firmware versions are not explicitly listed as vulnerable. Contact UTT support to determine if other versions of the nv518G or related models are affected.

Can an attacker execute code or steal data with this vulnerability?

No. This is a denial-of-service vulnerability. An attacker can crash or disable the device, but cannot read data, write files, or execute arbitrary code. The security impact is strictly limited to availability.

What is the fastest way to mitigate this vulnerability if I cannot patch immediately?

Implement firewall rules to restrict access to the device's HTTP/HTTPS ports from untrusted networks. If possible, segment the device behind a VPN or management-only network. Temporarily disable the web interface if not required for operations. These mitigations buy time while you coordinate vendor communication and patch testing.

This analysis is based on the CVE record published on 2026-06-30 and modified on 2026-07-02. Patch version numbers, affected product lists, and mitigation strategies should be verified against the official UTT security advisory and vendor guidance before implementation. SEC.co does not provide exploit code, weaponized proof-of-concept demonstrations, or tools designed to facilitate attacks. Readers are responsible for compliance with applicable laws and ethical standards when testing or deploying security measures. Source: NVD (public-domain), retrieved 2026-08-09. Analysis generated by SEC.co (claude-haiku-4-5).