CVE-2026-19505

Summary

Improper cryptographic signature verification in jst_functions.c in RDK-B WebUI rdkb-2025q4-kirkstone.04.10.26 allows a remote attacker to bypass authentication and obtain administrative access via a forged JWT containing an invalid RSA signature.

Affected Software

VendorProductVersion RangeStatus
RDKRDK-B WebUIrdkb-2025q4-kirkstoneaffected

Weaknesses

  • CWE-347 Improper Verification of Cryptographic Signature

References