PatchSiren cyber security CVE debrief
CVE-2026-19509 RDK CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T20:17:14.770Z and has not been modified since then. CVE-2026-19509 is a medium-severity vulnerability in RDK-B WebUI, allowing an authenticated attacker to cause denial of service via a crafted ssid_number parameter in ajaxSet_wireless_network_configuration.jst. This issue requires prompt review and potential patching to prevent exploitation. The vulnerability affects RDK-B WebUI versions rdkb-2025q4-kirkstone.04.10.26 and may impact organizations with exposed or internet-facing systems. Organizations using RDK-B WebUI, particularly those with exposed or internet-facing systems, should review and potentially patch this vulnerability. Affected operators, platforms, and security teams need to assess their deployments, verify system configurations, and consider compensating controls while remediation is scheduled and verified.
- Vendor
- RDK
- Product
- RDK-B WebUI
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-09-03
Who should care
Organizations using RDK-B WebUI, particularly those with exposed or internet-facing systems, should review and potentially patch this vulnerability. Affected operators, platforms, and security teams need to assess their deployments, verify system configurations, and consider compensating controls while remediation is scheduled and verified. Vulnerability management and security teams should prioritize this issue due to its potential impact on system availability and security posture.
Technical summary
CVE-2026-19509 is a medium-severity vulnerability in RDK-B WebUI, allowing an authenticated attacker to cause denial of service via a crafted ssid_number parameter in ajaxSet_wireless_network_configuration.jst. This issue requires prompt review and potential patching to prevent exploitation. The vulnerability affects RDK-B WebUI versions rdkb-2025q4-kirkstone.04.10.26 and may impact organizations with exposed or internet-facing systems.
Defensive priority
Authenticated denial of service vulnerability in RDK-B WebUI requires prompt review and potential patching.
Recommended defensive actions
- Review and potentially apply patches for RDK-B WebUI
- Verify and limit network exposure for affected systems
- Monitor system logs for potential exploitation attempts
Evidence notes
Official CVE Program record and NVD vulnerability detail page provide limited information on CVE-2026-19509; further review of source references may be necessary to understand the full scope of affected systems, potential impact, and recommended mitigations. Defenders should verify system configurations, review network exposure, and monitor for potential exploitation attempts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19509 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19509
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19509 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19509
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://developer.rdkcentral.com/documentation/documentation/rdk_broadband_documentation/components/webui/
-
Source reference
Unverified legacy reference
URL: https://whitehats.pwr.edu.pl//blog/2026-08-19-multiple-vulnerabilities-in-rdkb/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.