External risk intelligence

RDK-B WebUI Improper Cryptographic Signature Verification Allows Authentication Bypass

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-19505

The vulnerability resides in the RDK-B WebUI, which serves as the management interface for broadband gateway devices. These interfaces are frequently designed to be accessible via the network to allow for administrative configuration, often presenting an internet-facing or edge-reachable surface in many common deployment scenarios.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security vulnerability has been identified in the RDK-B WebUI, a component used in broadband gateway devices. This issue could allow an unauthorized remote attacker to bypass authentication and gain administrative control by exploiting a weakness in how digital signatures are verified. The primary concern is to determine if our environment utilizes this specific technology and assess any potential exposure.

  • Forged digital signatures grant unauthorized admin access.
  • Matters if RDK-B WebUI is in use.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker can reach the vulnerable component by sending a specially crafted JSON Web Token (JWT) to the RDK-B WebUI over the network. This forged token, containing an invalid RSA signature, tricks the `jst_functions.c` file into improperly verifying the signature. Successful exploitation bypasses authentication, granting the attacker administrative access.

  • Requires network access.
  • Triggered by forged JWT with invalid signature.
  • Grants administrative access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to bypass authentication and gain administrative control of the RDK-B WebUI by providing a forged JSON Web Token (JWT) with an invalid RSA signature.

  • Administrative access to RDK-B WebUI.
  • Bypass authentication via forged JWT.
  • Unauthorized system control.

Operational Fix

Recommended remediation, mitigation, and detection steps

The RDK-B WebUI is likely managed by the platform or infrastructure team responsible for broadband gateway devices, with potential coordination needed from security and vendor management. The first actionable step is to identify all instances of this WebUI, assess their network reachability and business criticality, and confirm the accountable owner before planning remediation.

  • Platform or infrastructure teams own this issue.
  • Verify external reachability and ownership.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is RDK-B WebUI and what is it used for?

RDK-B (Reference Design Kit for Broadband) WebUI is a management interface embedded in broadband gateway devices. It provides the administrative control panel that allows users and service providers to configure network settings, monitor connectivity, and manage device functions through a web browser.

What does CVE-2026-19505 mean by improper signature verification?

This vulnerability, classified as CWE-347, occurs when the software fails to properly check the digital signature of a JSON Web Token (JWT). Because the system incorrectly validates the RSA signature, it can be tricked into accepting a forged token as legitimate, allowing an attacker to bypass standard login procedures.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a specially crafted, forged JSON Web Token (JWT) to the WebUI over the network. It is important to note that the vulnerability specifically involves an invalid RSA signature; providing a valid or non-forged token does not trigger this bypass, nor does it affect standard, non-administrative traffic.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal indicates that RDK-B WebUI is often deployed on broadband gateways in ways that make them internet-facing or edge-reachable. Because this component is designed for network-based management, any instance reachable from the network may be considered a relevant surface for this vulnerability.

What are the first steps to take if I run RDK-B WebUI?

Begin by identifying all devices in your infrastructure running the affected RDK-B WebUI version. Once identified, evaluate the network reachability of these interfaces to determine if they are exposed to untrusted networks. Coordinate with your platform or infrastructure team to confirm ownership and track the availability of updates from your vendor.

References