Impact
A stack buffer overflow exists in the administrative web interface of the Mercusys MW302R router. The overflow allows an authenticated user with administrative privileges to send a specially crafted request that manipulates the control flow to an arbitrary instruction address, causing the device to crash. This flaw is a classic buffer overflow (CWE-121) and results in a denial of service, preventing legitimate administrative access until the router is rebooted or patched.
Affected Systems
The vulnerability affects Mercusys MW302R routers running firmware version 1.1.4.10 Build 231023, specifically the EU variant. No other vendors or products are listed as impacted.
Risk and Exploitability
Because the flaw requires administrative authentication, the attack vector is likely local or internal, possibly from a compromised user. The CVSS score of 5.7 indicates medium severity, while the EPSS score of <1% and lack of inclusion in CISA's KEV catalog suggest that exploitation is currently unlikely to be widely observed. Nevertheless, an attacker who can authenticate to the administrative interface can bring the router down, disrupting network connectivity until reboot or patching occurs.
OpenCVE Enrichment