THE content outlines critical security vulnerabilities in the RDK-B WebUI, with five flaws disclosed by CERT/CC on August 19, 2026. The most severe vulnerability, CVE-2026-19505, allows unauthenticated remote attackers to bypass login and gain admin control over broadband gateways. Other notable issues include a login race condition (CVE-2026-19506) and memory corruption (CVE-2026-19508). No patches are currently available, and exploitation in the wild remains unconfirmed. It is advised to limit access to the WebUI and restrict it to trusted networks while awaiting a resolution.
RDK-B WebUI Vulnerabilities Let Attackers Bypass Login
CyberSIXT Evidence Panel
Article by CyberSIXT