Impact
The vulnerability arises from insufficient input validation in the ajaxSet_wireless_network_configuration.jst component of the RDK‑B WebUI. A crafted ssid_number value can trigger a denial‑of‑service condition for an authenticated user, causing the WebUI service to become unresponsive or crash. This flaw is confined to the web interface and does not provide code execution, data exfiltration, or other privileges.
Affected Systems
Manufacturers and operators deploying the RDK‑B WebUI firmware rdkb‑2025q4‑kirkstone.04.10.26 are impacted; any device running that specific firmware without an update is vulnerable.
Risk and Exploitability
Because the flaw requires authenticated web‑interface access, only insiders or actors with compromised credentials can exploit it. The CVSS score is 6.5, indicating medium severity. The EPSS score is < 1% and the issue is not listed in the CISA KEV catalog, indicating a low to moderate likelihood of widespread exploitation. Nonetheless, an attacker who can reach the interface can repeatedly provoke service disruptions, so monitoring for anomalous ssid_number requests is recommended until an official vendor update is released.
OpenCVE Enrichment