A vulnerability has been found in UTT HiPER 810 1.7.4-141218. This issue affects the function setSysAdm of the file /goform/formUser. The manipulation of the argument passwd1 leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Fri, 13 Feb 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Utt 810
Utt 810 Firmware
CPEs cpe:2.3:h:utt:810:4.0:*:*:*:*:*:*:*
cpe:2.3:o:utt:810_firmware:1.7.4-141218:*:*:*:*:*:*:*
Vendors & Products Utt 810
Utt 810 Firmware

Tue, 10 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 09 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Utt
Utt hiper 810
Vendors & Products Utt
Utt hiper 810

Sat, 07 Feb 2026 09:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in UTT HiPER 810 1.7.4-141218. This issue affects the function setSysAdm of the file /goform/formUser. The manipulation of the argument passwd1 leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title UTT HiPER 810 formUser setSysAdm command injection
Weaknesses CWE-74
CWE-77
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2026-02-07T09:02:06.706Z

Updated: 2026-02-10T15:38:59.986Z

Reserved: 2026-02-06T08:00:39.436Z

Link: CVE-2026-2080

cve-icon Vulnrichment

Updated: 2026-02-10T15:38:56.448Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-07T09:16:01.593

Modified: 2026-02-13T18:49:08.830

Link: CVE-2026-2080

cve-icon Redhat

No data.