Impact
The vulnerability is a stack‑based buffer overflow in the sub_44D844 function of the /goform/get_hidessid_cfg page on the LB‑LINK BL‑WR9000 router. Sending a specially crafted request that overflows the buffer can corrupt memory, potentially allowing an attacker to execute arbitrary code or crash the web interface. The weakness is classified as CWE‑119, CWE‑120, and CWE‑125.
Affected Systems
The affected product is the LB‑LINK BL‑WR9000 router, firmware version 2.4.9. Only this firmware revision is listed in the CVE data, and no other versions or related products are indicated.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the EPSS score is below 1 %, suggesting limited evidence of widespread exploitation. The description explicitly states that the attack can be initiated remotely, implying that an external attacker could target an exposed router via its web interface. No official fix has been reported by the vendor in the supplied data, increasing the risk for devices that remain accessible.
OpenCVE Enrichment