SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-19505

CRITICAL · CVSS 9.8 EPSS 0.39%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability in RDK-B WebUI's `jst_functions.c` allows remote attackers to bypass authentication by exploiting improper cryptographic signature verification, enabling them to gain administrative access through a forged JSON Web Token (JWT) with an invalid RSA signature. Organizations utilizing the specified version of RDK-B WebUI should prioritize addressing this issue to mitigate the risk of unauthorized access and potential system compromise. Immediate action is recommended for those managing web interfaces that rely on this component.

CVE
CVE-2026-19505
Severity
CRITICAL
CVSS
9.8
EPSS
0.39%

Original NVD Description

Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to bypass authentication and obtain administrative access via a forged JWT containing an invalid RSA signature.