nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-4464 CVE-2021-4464
CRITICAL
FIberHome AN5506-04-FA / HG6245D Routers Remote Stack Overflow
Record summary
CVE-2021-4464 has a selected CVSS score of 9.3 (critical).
Description
FiberHome AN5506-04-FA firmware versions up to and including RP2631 and HG6245D prior to RP2602 contain a stack-based buffer overflow, as the HTTP service ('webs') fails to enforce maximum lengths for Cookie header values. When a cookie longer than 511 bytes is processed, a stack buffer is overrun, leading to a crash or potential control of execution flow.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 13, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
AN5506-04-FABrowse FiberHome / AN5506-04-FADefault status: unaffected | CVE List | Through RP2631 | affected |
HG6245DBrowse FiberHome / HG6245DDefault status: unaffected | CVE List | Before RP2602 | affected |
References
4pierrekim.github.ioTechnical descriptionexploit
https://pierrekim.github.io/advisories/2021-fiberhome-0x00-ont.txt pierrekim.github.ioTechnical descriptionexploit
https://pierrekim.github.io/blog/2021-01-12-fiberhome-ont-0day-vulnerabilities.html vulncheck.comThird-party advisory
https://www.vulncheck.com/advisories/fiberhome-routers-remote-stack-overflow