CVE-2026-19509: RDK WebUI DOS vulnerability
Published Aug 19, 2026
·Updated
Improper input validation in ajaxSetwirelessnetworkconfiguration.jst in RDK-B WebUI rdkb-2025q4-kirkstone.04.10.26 allows an authenticated attacker to cause denial of service via a crafted ssidnumber parameter.
Affected Software
1 affected component
RDK RDK-B WebUI=rdkb-2025q4-kirkstone.04.10.26
Event History
Aug 19, 2026
CVE Published
via MITRE·07:28 PM
Data Sourced
via MITRE·07:28 PM
DescriptionWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker must be authenticated to the RDK-B WebUI. The available information does not indicate that unauthenticated requests can trigger the denial of service.
2
Which component and request parameter should be prioritized for review?
Review the ajaxSet_wireless_network_configuration.jst endpoint, specifically handling of the ssid_number parameter. The denial of service is triggered by a crafted value for that parameter.
3
How can I determine whether my deployment is affected?
Verify whether the device uses RDK-B WebUI rdkb-2025q4-kirkstone.04.10.26 and exposes the affected wireless network configuration endpoint to authenticated users.