Impact
Improper verification of cryptographic signatures in the WebUI's jst_functions.c module allows an attacker to present a forged JSON Web Token with an invalid RSA signature. By bypassing the authentication check, the attacker can log in as an administrative user and gain full control over the device's configuration and functionality. The weakness is a classic authentication bypass, meaning confidentiality, integrity, and availability are all at risk when an unauthenticated actor can assume privileged roles.
Affected Systems
This issue affects the RDK-B WebUI component released as rdkb-2025q4-kirkstone.04.10.26, developed by RDK. Devices running this exact release, or those that have not applied a remedial update, are vulnerable.
Risk and Exploitability
The vulnerability permits remote authentication bypass, allowing attackers to craft a JWT with an invalid RSA signature and bypass the WebUI's authentication checks. The EPSS score, less than 1%, indicates a low but nonzero chance of exploitation. Although not listed in CISA's KEV catalog, its potential to grant unrestricted administrative control renders it a high-priority concern. Based on the description, it is inferred that an attacker could remotely exploit this flaw by sending a specially crafted JWT to the WebUI. With a CVSS score of 9.8, the vulnerability is classified as critical, underscoring the need for immediate remediation.
OpenCVE Enrichment