Impact
The RDK-B WebUI contains a heap-based buffer overflow in the multipart form-data parser implemented in jst_post.c. A specially crafted multipart form-data request can corrupt memory, cause a denial of service, and potentially enable arbitrary code execution by a remote attacker without authentication.
Affected Systems
The vulnerability affects the RDK-B WebUI component of the RDK consortium, specifically the rdkb-2025q4-kirkstone.04.10.26 release. No other releases are listed as affected. The product is a web interface used in broadband routers.
Risk and Exploitability
The flaw can be exploited from any network that reaches the WebUI, with no authentication required. The CVSS score of 9.8 indicates critical severity. EPSS score of <1% indicates a very low probability of exploitation, and the issue is not listed in CISA’s KEV catalog, yet the remote code execution potential makes it a high-risk vulnerability. The attack vector is inferred to be a malformed multipart form‑data HTTP request sent to the WebUI, though no public exploit evidence is currently documented.
OpenCVE Enrichment