CVE-2026-19505
RDK RDK-B WebUI
Improper cryptographic signature verification in `jst_functions.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to bypass authentication and obtain administrative access via a forged JWT containing an invalid RSA signature.
- CVSS
- 9.8
- EPSS
- 0.39% 32.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.08.20