VU#874418: RDK-B WebUI contains multiple vulnerabilities

Imported from official source

Advisory

Cybersecurity Classified by Officially

Overview

RDK Central RDK-B WebUI version, rdkb-2025q4-kirkstone, contains multiple vulnerabilities involving memory corruption, improper authentication, race conditions, and insufficient input validation. An attacker with network access to an affected WebUI may be able to bypass authentication, obtain administrative access, cause a denial-of-service condition, or corrupt memory within underlying RDK-B processes. Under certain conditions, this memory corruption may potentially be leveraged for arbitrary code execution.

Description

RDK-B (Reference Design Kit for Broadband) is an open-source software platform used in broadband gateways and related networking devices. The RDK-B WebUI provides a web-based interface for configuring and administering an RDK-B device. Five vulnerabilities have been identified in the RDK-B WebUI.

CVE-2026-19505JWT (JSON Web Token) authentication in javascript-templates/source/jst_functions.c does not correctly verify whether a token's cryptographic signature is valid. The application treats both a valid signature and an invalid signature as successful verification because it incorrectly checks the return value from OpenSSL's EVP_VerifyFinal() function.
A remote, unauthenticated attacker can craft a JWT with an invalid signature that is still accepted by the WebUI. Successful exploitation allows the attacker to log in as the privileged user and gain administrative access to the device.

CVE-2026-19506 The login process in /usr/www2/check.jst uses a shared value to store the result of password verification. Because this value is shared between multiple requests, the application may return one user's authentication result to another user's session.
An unauthenticated attacker can send a login request at the same time a legitimate administrator logs in. If the requests are timed correctly, the attacker's session may receive the administrator's successful authentication result, allowing access to the WebUI without knowing the correct password.

This is an extract. The publication continues at the source.

Read the original at the source: https://kb.cert.org/vuls/id/874418

Officially imported this from CERT Coordination Center’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

This publication has changed since it was first published

2 versions recorded. The original is kept in full — nothing is overwritten.

  1. v2 imported change on current
  2. v1 as first published on

Provenance

Organization
CERT Coordination Center — imported from official source
Official source
https://www.kb.cert.org/vuls/atomfeed/ ATOM
Imported
September 15, 2026 20:57
Versions
2 recorded
Identity
https://kb.cert.org/vuls/id/874418

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.