CyberRota Analysis
AI-GeneratedImproper input validation in the `ajaxSet_wireless_network_configuration.jst` file of the RDK-B WebUI allows authenticated attackers to exploit the `ssid_number` parameter, potentially leading to a denial of service. Organizations using the specified version of RDK-B should prioritize addressing this vulnerability to prevent service disruptions. Immediate action is recommended for those managing affected systems to mitigate potential impacts.
CVE
CVE-2026-19509
Severity
MEDIUM
CVSS
6.5
EPSS
0.32%
Original NVD Description
Improper input validation in `ajaxSet_wireless_network_configuration.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows an authenticated attacker to cause denial of service via a crafted `ssid_number` parameter.