VDB
CVE-2026-19505
CVE-2026-19505
PUBLISHED
Reported by certcc · Published August 19, 2026
Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to bypass authentication and obtain administrative access via a forged JWT containing an invalid RSA signature.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| RDK | RDK-B WebUI | rdkb-2025q4-kirkstone |
| RDK | RDK-B WebUI | rdkb-2025q4-kirkstone |
Timeline
- Aug 19, 2026 CVE Published
- Aug 19, 2026 CVE Updated
- Aug 22, 2026 Coalition ESS Score