VU#874418: RDK-B WebUI contains multiple vulnerabilities

2026-08-19T20:52:01Z9d9d361ab369be5eac541a8553094c5af54f03ab9dd64f426a7e79011e0511c5
CVE-2026-15969CVE-2026-15971CVE-2026-15974CVE-2026-15976CVE-2026-16503CVE-2026-16504CVE-2026-18412CVE-2026-18497CVE-2026-19505CVE-2026-19506CVE-2026-6726CVE-2026-6727CVE-2026-8496CERT/CCOpenCartRCERDK-BSGLangSOGoSSRFTPM-2.0VPS.orgXSSactively-exploitedauthentication-bypasscredential-exposuredefault-passwordsdirectory-traversalheap-buffer-overflowinformation-disclosuremultiple-vulnerabilitiesremote-code-executionstb_truetypetiming-side-channel

What happened

CERT/CC vulnerability notes covering multiple products and components, including RDK-B WebUI authentication bypass and memory corruption, TPM 2.0 information leakage and timing side channels, OpenCart directory traversal leading to potential code execution, stb TrueType heap buffer overflow, actively exploited SOGo XSS with potential mailbox compromise, VPS.org templates exposing default credentials and insecure services, and SGLang vulnerabilities enabling unauthenticated RCE, SSRF, local file read, credential disclosure, and model exfiltration. Several issues are remotely exploitable, lack a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
9d9d361ab369be5eac541a8553094c5af54f03ab9dd64f426a7e79011e0511c5
Enrichment time
2026-08-19T20:52:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · VU#874418: RDK-B WebUI contains multiple vulnerabilities · Baitaphish