Impact
The vulnerability is a stack-based buffer overflow in the http_gdpr_decrypt function of the Mercusys MB115-4G web interface. An attacker who can send a specially crafted request to the /cgi/login endpoint can corrupt memory, causing the httpd process to crash. Once crashed, the web administration service becomes unavailable, effectively treating the device as offline for management purposes.
Affected Systems
The issue affects all firmware builds of the Mercusys MB115-4G that predate the security update to V1_1.9.0. No other products or later firmware versions are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity for a remote unauthenticated denial-of-service. The EPSS score of < 1% suggests a low likelihood of exploitation. The absence of a KEV listing does not negate risk. The attack vector is inferred to be remote over the network, requiring only that the attacker reach the device’s web interface and send a malicious request; no authentication is needed. Repeated exploitation can render the device's management interface inoperable, leading to service disruption.
OpenCVE Enrichment