VYPR
Vendor

RDK B

Products
2
CVEs
5
Across products
5
Status
Private

Products

2

Recent CVEs

5
  • CVE-2026-19508CriAug 19, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in the multipart form-data parser in `jst_post.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause memory corruption and denial of service, and potentially execute arbitrary code, via a crafted…

  • CVE-2026-19505CriAug 19, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to bypass authentication and obtain administrative access via a forged JWT containing an invalid RSA signature.

  • CVE-2026-19506HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    Race condition in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to gain unauthorized access via concurrent authentication requests that exploit shared authentication state.

  • CVE-2026-19507HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.00

    Uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause denial of service via excessively large password values.

  • CVE-2026-19509MedAug 19, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper input validation in `ajaxSet_wireless_network_configuration.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows an authenticated attacker to cause denial of service via a crafted `ssid_number` parameter.