VU#874418: RDK-B WebUI contain... Note

VU#874418: RDK-B WebUI contains multiple vulnerabilities

The RDK-B WebUI version rdkb-2025q4-kirkstone harbors multiple critical vulnerabilities. These weaknesses include problems with memory corruption, improper authentication, race conditions, and insufficient input validation. An attacker connected to the network could potentially bypass authentication and gain administrative control. These vulnerabilities can also lead to denial-of-service conditions by corrupting memory in underlying RDK-B processes. In some scenarios, this memory corruption might even allow for arbitrary code execution. One specific flaw involves JWT authentication that fails to properly verify cryptographic signatures. Another race condition in the login process can allow an attacker to inherit another user's authentication result. A vulnerability in the login handler allows for denial-of-service by submitting excessively large password values. A data parser flaw can lead to memory corruption and potential code execution due to malformed input. Finally, an authenticated administrator can cause denial-of-service and potential code execution by triggering memory corruption in the rtrouted process. Due to the lack of a coordinated update from RDK Central, users are advised to restrict WebUI access to trusted networks and authorized hosts.