securityonline.info 8/21/2026, 3:20:48 PM · external

RDK-B WebUI Vulnerabilities Let Attackers Bypass Login

RDK-B WebUI Vulnerabilities Let Attackers Bypass Login
CyberSIXT Evidence Panel

THE content outlines critical security vulnerabilities in the RDK-B WebUI, with five flaws disclosed by CERT/CC on August 19, 2026. The most severe vulnerability, CVE-2026-19505, allows unauthenticated remote attackers to bypass login and gain admin control over broadband gateways. Other notable issues include a login race condition (CVE-2026-19506) and memory corruption (CVE-2026-19508). No patches are currently available, and exploitation in the wild remains unconfirmed. It is advised to limit access to the WebUI and restrict it to trusted networks while awaiting a resolution.

View Primary Source Via securityonline.info

Article by CyberSIXT