Skip to main content
HIGH

CVE-2026-2118

UTT HiPER 810 rehttpd formReleaseConnect sub_4407D4 command injection

CVSS v3

7.2

HIGH

EPSS Score

4.4 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

A vulnerability was determined in UTT HiPER 810 1.7.4-141218. The impacted element is the function sub_4407D4 of the file /goform/formReleaseConnect of the component rehttpd. Executing a manipulation of the argument Isp_Name can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

Technical details

Published
2026-02-08
Last Modified
2026-02-13

Frequently asked questions

What is CVE-2026-2118?

A vulnerability was determined in UTT HiPER 810 1.7.4-141218. The impacted element is the function sub_4407D4 of the file /goform/formReleaseConnect of the component rehttpd. Executing a manipulation of the argument Isp_Name can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

Is CVE-2026-2118 actively exploited?

A proof-of-concept exploit exists for CVE-2026-2118, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2026-2118?

CVE-2026-2118 has a CVSS v3 base score of 7.2 (HIGH severity).

Is CVE-2026-2118 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key