What is CVE-2026-2847?
A vulnerability was detected in UTT HiPER 520 1.7.7-160105. Affected is the function sub_44EFB4 of the file /goform/formReleaseConnect of the component Web Management Interface. The manipulation of the argument Isp_Name results in os command injection. The attack can be launched remotely. The exploit is now public and may be used.
Timeline
- 2026-02-20Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-17NVD record last updated
Affected product
Utt 520 Firmware
NVD also lists CPE entries for: Utt 520 Firmware, Utt 520
Remediation Steps
- Immediately update ASDA-Soft to the latest patched version from Delta Electronics
- Isolate affected systems from network if patching cannot be completed within 2 hours
- Review audit logs for unauthorized code execution attempts in the past 30 days
- Deploy network segmentation to restrict ASDA-Soft system access to authorized personnel only
- Monitor for suspicious process execution and file modifications on affected servers
References
- https://github.com/cha0yang1/UTT520CVE/blob/main/UTTRCE2.md
- https://vuldb.com/?id.347083
- https://vuldb.com/?submit.753965
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-106-01.json
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-2847
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 3 of April 2026 (April 20 – 26)
- Vulnerability Priority Report – Week 5 of March 2026 (March 30 – April 5)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.