CVE-2026-78169 scores 9.9 on CVSS, and that decimal point deserves scrutiny. The missing 0.1 likely reflects the administrative function requirement baked into scoring models designed for supported software with defined patch timelines. For the UTT HiPER 1250GW, that distinction is academic — the firmware shipped in September 2021, the device is almost certainly end-of-life, and the strcpy overflow in /goform/aspRemoteApConfTempSend sits in a network-adjacent HTTP handler processing user-supplied strings. That's an RCE pre-condition regardless of the score.
The real analytical problem is temporal, not technical. For enterprise software, a five-year exposure window is bounded by patch cycles. For consumer-grade networking equipment, this window typically means the hardware is already abandoned by its vendor, no patches will arrive, and any devices still running affected firmware are living on borrowed time with a public exploit now available. The CVSS vector assumes remediation is possible; here it likely isn't.
If you manage networks containing these devices, the priority is immediate network segmentation — treat the router as a compromised foothold until proven otherwise. Full hardware replacement is the only solution that collapses the exploit surface permanently, and it should be treated as mandatory for any device handling sensitive traffic behind this perimeter. Segmentation slows the blast radius but doesn't eliminate the foothold an attacker already has when the vulnerability is remotely triggerable via HTTP.
The installed base is unknowable. There's no telemetry from these devices sitting in home networks, SOHO offices, and ISP-provided hardware pools in regional markets. Assume the exposure is wider than you can measure. The existence of a public CVE with this severity score, combined with accessible exploitation frameworks, means the marginal cost of attacking this device has collapsed — what was once a dedicated exploit development exercise is now a Shodan query and a module run.