Impact
Uncontrolled resource consumption occurs in the check.jst file of RDK‑B WebUI when a remote unauthenticated attacker submits an excessively large password value. The input is processed in a way that can exhaust memory or processing resources, leading to a denial of service. This results in loss of availability for users who rely on the WebUI interface.
Affected Systems
The vulnerability is present in the RDK‑B WebUI component for version rdkb‑2025q4‑kirkstone.04.10.26. Systems running this build of RDK‑B WebUI are directly affected; other RDK products are not cited as vulnerable in the available data.
Risk and Exploitability
The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 7.5 indicates high severity. The attack vector is remote and unauthenticated; an attacker only needs to access the WebUI and supply an oversized password field. Because the flaw manifests as a denial of service, successful exploitation can cause service interruption for legitimate users, particularly if the WebUI is exposed to the internet. No vendor patch is indicated in the CVE description, so the mitigation status remains unknown.
OpenCVE Enrichment