CVE-2026-2847: Utt 520 Firmware

High severity, CVSS 7.2. EPSS: 7.7% chance of exploitation in the next 30 days.

A vulnerability was detected in UTT HiPER 520 1.7.7-160105. Affected is the function sub_44EFB4 of the file /goform/formReleaseConnect of the component Web Management Interface. The manipulation of the argument Isp_Name results in os command injection. The attack can be launched remotely. The exploit is now public and may be used.

Affected products

  • Utt 520 Firmware: version 1.7.7-160105 only

Published 2026-02-20. Last modified 2026-06-17.