PatchSiren cyber security CVE debrief
CVE-2026-19507 RDK CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T20:17:14.513Z and has not been modified since then. This CVE-2026-19507 vulnerability involves uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26`, allowing a remote unauthenticated attacker to cause denial of service via excessively large password values. Organizations should review their inventory for potential exposure and implement defensive measures. The vulnerability has a CVSS score of 7.5 and HIGH severity. Affected systems may experience service disruption due to resource exhaustion. Defensive measures should focus on monitoring for excessively large password values and verifying vendor remediation.
- Vendor
- RDK
- Product
- RDK-B WebUI
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-09-03
Who should care
Organizations using RDK-B WebUI systems, particularly those with public-facing interfaces, should review and verify their inventory for potential exposure and implement defensive measures. Operators of RDK-B WebUI systems should assess their vulnerability management processes and ensure that security teams are aware of the potential impact on their platforms. Vulnerability management and security teams should prioritize review of affected systems and coordinate with vendors for remediation.
Technical summary
Uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause denial of service via excessively large password values. This vulnerability has a CVSS score of 7.5 and HIGH severity. Affected systems may experience service disruption due to resource exhaustion. Defensive measures should focus on monitoring for excessively large password values and verifying vendor remediation.
Defensive priority
High-priority defensive review recommended due to potential for denial of service via excessively large password values.
Recommended defensive actions
- Review and verify inventory of RDK-B WebUI systems for potential exposure
- Implement monitoring for excessively large password values
- Consider compensating controls for unauthenticated access
- Verify vendor remediation and patch application
Evidence notes
Evidence from official CVE Program record and NIST NVD detail page indicates uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26`. Limited detail available on affected scope and vendor remediation. Further review of RDK-B WebUI documentation and vulnerability blog posts may provide additional context for defenders. Verify vendor remediation and patch application status for potential exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19507 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19507
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19507 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19507
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://developer.rdkcentral.com/documentation/documentation/rdk_broadband_documentation/components/webui/
-
Source reference
Unverified legacy reference
URL: https://whitehats.pwr.edu.pl//blog/2026-08-19-multiple-vulnerabilities-in-rdkb/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.