VU#874418: RDK-B WebUI contains multiple vulnerabilities
2026-08-19T20:52:01Z•9d9d361ab369be5eac541a8553094c5af54f03ab9dd64f426a7e79011e0511c5
CVE-2026-15969CVE-2026-15971CVE-2026-15974CVE-2026-15976CVE-2026-16503CVE-2026-16504CVE-2026-18412CVE-2026-18497CVE-2026-19505CVE-2026-19506CVE-2026-6726CVE-2026-6727CVE-2026-8496CERT/CCOpenCartRCERDK-BSGLangSOGoSSRFTPM-2.0VPS.orgXSSactively-exploitedauthentication-bypasscredential-exposuredefault-passwordsdirectory-traversalheap-buffer-overflowinformation-disclosuremultiple-vulnerabilitiesremote-code-executionstb_truetypetiming-side-channel
What happened
CERT/CC vulnerability notes covering multiple products and components, including RDK-B WebUI authentication bypass and memory corruption, TPM 2.0 information leakage and timing side channels, OpenCart directory traversal leading to potential code execution, stb TrueType heap buffer overflow, actively exploited SOGo XSS with potential mailbox compromise, VPS.org templates exposing default credentials and insecure services, and SGLang vulnerabilities enabling unauthenticated RCE, SSRF, local file read, credential disclosure, and model exfiltration. Several issues are remotely exploitable, lack a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 9d9d361ab369be5eac541a8553094c5af54f03ab9dd64f426a7e79011e0511c5
- Enrichment time
- 2026-08-19T20:52:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.