Impact
Race condition in the WebUI authentication script allows a remote attacker to send several authentication requests simultaneously, causing the shared authentication state to be misused and granting access without proper credentials. The vulnerability results in direct unauthorized access to the device, potentially exposing configuration interfaces and sensitive data. It is an exploitation of a concurrency flaw in the authentication mechanism.
Affected Systems
The flaw affects the RDK-B WebUI component, specifically version rdkb-2025q4-kirkstone.04.10.26. Any RDK-B device running this version of the WebUI is susceptible to the concurrent request attack.
Risk and Exploitability
The attack vector is remote, requiring the attacker to be able to send HTTP requests to the device. The CVSS score is 8.1 and the EPSS score is below 1%, indicating a high severity vulnerability with a low estimated exploitation likelihood. The exploit is reproducible by sending rapid, overlapping authentication attempts, but the low EPSS score suggests that actual exploitation is unlikely in typical environments. The vulnerability is not listed in the CISA KEV catalog, but the absence of mitigations or a patch increases the practical risk.
OpenCVE Enrichment