VU#874418: RDK-B WebUI contains multiple vulnerabilities

Date Aug 19, 2026
Type Coordinated disclosure
Signal Patch review
Vendor / Product RDK-B · WebUI
Patch review

Summary

Overview RDK Central RDK-B WebUI version, rdkb-2025q4-kirkstone, contains multiple vulnerabilities involving memory corruption, improper authentication, race conditions, and insufficient input validation. An attacker with network access to an affected WebUI may be able to bypass authentication, obtain administrative access, cause a denial-of-service condition, or corrupt memory within underlying RDK-B processes. Under certain conditions, this memory corruption may potentially be leveraged for arbitrary code execution. Description RDK-B (Reference Design Kit for Broadband) is an open-source software platform used in broadband gateways and related networking devices. The RDK-B WebUI provides a web-based interface for configuring and administering an RDK-B device. Five vulnerabilities have been identified in the RDK-B WebUI. CVE-2026-19505... Related CVEs: CVE-2026-19505, CVE-2026-19506, CVE-2026-19507, CVE-2026-19508.

Why it matters

CERT/CC notes often cover coordinated disclosures, multi-vendor exposure, infrastructure risk, or cases where remediation guidance is still developing.

Operator check

Review the CERT/CC Vulnerability Note and compare the affected vendor and product list against your inventory. Apply vendor fixes or compensating controls for WebUI where available.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.