A security vulnerability has been detected in UTT HiPER 520 1.7.7-160105. This impacts the function sub_44D264 of the file /goform/formPdbUpConfig of the component Web Management Interface. The manipulation of the argument policyNames leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Feb 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in UTT HiPER 520 1.7.7-160105. This impacts the function sub_44D264 of the file /goform/formPdbUpConfig of the component Web Management Interface. The manipulation of the argument policyNames leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. | |
| Title | UTT HiPER 520 Web Management formPdbUpConfig sub_44D264 os command injection | |
| Weaknesses | CWE-77 CWE-78 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-02-20T15:32:06.824Z
Updated: 2026-02-20T15:32:06.824Z
Reserved: 2026-02-20T07:59:46.096Z
Link: CVE-2026-2846
No data.
Status : Awaiting Analysis
Published: 2026-02-20T16:22:45.360
Modified: 2026-02-20T16:55:22.933
Link: CVE-2026-2846
No data.