CVE-2026-19509
Received Received - Intake

Improper Input Validation in RDK-B WebUI Leading to DoS

Vulnerability report for CVE-2026-19509, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: CERT/CC

Description

Improper input validation in `ajaxSet_wireless_network_configuration.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows an authenticated attacker to cause denial of service via a crafted `ssid_number` parameter.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper input validation flaw in the RDK-B WebUI component. It exists in the file ajaxSet_wireless_network_configuration.jst and is triggered by a crafted ssid_number parameter. An authenticated attacker can exploit this to cause a denial of service condition.

Impact Analysis

If you use the affected RDK-B WebUI version, an attacker with valid credentials could send a maliciously crafted request to disrupt wireless network configuration services. This may lead to temporary unavailability of network management features.

Mitigation Strategies

Update the RDK-B WebUI to a patched version. Remove or restrict access to the vulnerable file ajaxSet_wireless_network_configuration.jst. Monitor network traffic for unusual SSID parameter manipulation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19509. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart