Description
Uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause denial of service via excessively large password values.
Published: 2026-08-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Uncontrolled resource consumption occurs in the check.jst file of RDK‑B WebUI when a remote unauthenticated attacker submits an excessively large password value. The input is processed in a way that can exhaust memory or processing resources, leading to a denial of service. This results in loss of availability for users who rely on the WebUI interface.

Affected Systems

The vulnerability is present in the RDK‑B WebUI component for version rdkb‑2025q4‑kirkstone.04.10.26. Systems running this build of RDK‑B WebUI are directly affected; other RDK products are not cited as vulnerable in the available data.

Risk and Exploitability

The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 7.5 indicates high severity. The attack vector is remote and unauthenticated; an attacker only needs to access the WebUI and supply an oversized password field. Because the flaw manifests as a denial of service, successful exploitation can cause service interruption for legitimate users, particularly if the WebUI is exposed to the internet. No vendor patch is indicated in the CVE description, so the mitigation status remains unknown.

Generated by OpenCVE AI on August 28, 2026 at 05:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply vendor’s patch or upgrade to a newer RDK‑B WebUI build that eliminates the unchecked password length handling.
  • Restrict inbound traffic to the WebUI interface with firewall rules or network segmentation to limit exposure to potential attackers.
  • Implement server‑side validation to reject password values that exceed a reasonable maximum length, reducing the chance of resource exhaustion.

Generated by OpenCVE AI on August 28, 2026 at 05:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Thu, 27 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Thu, 20 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Rdk
Rdk rdk-b Webui
Vendors & Products Rdk
Rdk rdk-b Webui

Thu, 20 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Wed, 19 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description Uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause denial of service via excessively large password values.
Title RDK WebUI uncontrolled resource consumption
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-08-27T15:39:20.176Z

Reserved: 2026-08-10T19:14:02.914Z

Link: CVE-2026-19507

cve-icon Vulnrichment

Updated: 2026-08-27T15:37:32.796Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T20:17:14.513

Modified: 2026-09-03T17:42:23.907

Link: CVE-2026-19507

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T06:00:14Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption