FiberHome AN5506-04-FA firmware versions up to and including RP2631 and HG6245D prior to RP2602 contain a stack-based buffer overflow, as the HTTP service ('webs') fails to enforce maximum lengths for Cookie header values. When a cookie longer than 511 bytes is processed, a stack buffer is overrun, leading to a crash or potential control of execution flow.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 12 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Description FiberHome AN5506-04-FA firmware versions up to and including RP2631 and HG6245D prior to RP2602 contain a stack-based buffer overflow, as the HTTP service ('webs') fails to enforce maximum lengths for Cookie header values. When a cookie longer than 511 bytes is processed, a stack buffer is overrun, leading to a crash or potential control of execution flow.
Title FIberHome AN5506-04-FA / HG6245D Routers Remote Stack Overflow
Weaknesses CWE-121
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-11-12T22:09:20.835Z

Reserved: 2025-11-12T21:24:45.845Z

Link: CVE-2021-4464

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-12T22:15:42.027

Modified: 2025-11-12T22:15:42.027

Link: CVE-2021-4464

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.