AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T20:17:14.770Z and has not been modified since then. CVE-2026-19509 is a medium-severity vulnerability in RDK-B WebUI, allowing an authenticated attacker to cause denial of service via a crafted ssid_number parameter in ajaxSet_wireless_network_configuration.jst. This issue requires prompt review [truncated]
The CVE-2026-19508 vulnerability is a heap-based buffer overflow in the multipart form-data parser in `jst_post.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26`. This critical vulnerability allows a remote unauthenticated attacker to cause memory corruption and denial of service, and potentially execute arbitrary code, via a crafted multipart/form-data request. Organizations using RDK-B WebUI, security [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T20:17:14.513Z and has not been modified since then. This CVE-2026-19507 vulnerability involves uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26`, allowing a remote unauthenticated attacker to cause denial of service via excessively large password val [truncated]
CVE-2026-19506 is a race condition vulnerability in `check.jst` of RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26`. This allows remote attackers to gain unauthorized access through concurrent authentication requests that exploit shared authentication state. Organizations using RDK-B WebUI, especially those with exposed web interfaces, should be aware of this vulnerability and take mitigation steps. The CVE r [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T20:17:14.150Z and has not been modified since then. The vulnerability, CVE-2026-19505, involves improper cryptographic signature verification in `jst_functions.c` of RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26`, allowing remote attackers to bypass authentication via a forged JWT with an invalid R [truncated]