Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rdkcentral

First CVE: Jun 20, 2019Active for: 7 yearsTotal CVEs: 48
14.2
VTI Score
Low

RDK Central develops the Reference Design Kit for Broadband (RDK-B), a modular firmware platform widely deployed across cable set-top boxes, gateways, and residential broadband devices. The vendor's vulnerability footprint, while concentrated in a narrowly scoped product line, carries outsized importance because firmware flaws in these edge devices can affect large populations of home networks and potentially serve as pivots into broader infrastructure. The exposure recurs through memory-safety and access-control weakness classes—out-of-bounds reads and writes, missing authorization checks, and improper exception handling—that are characteristic of C-based embedded codebases operating with minimal isolation. Defenders managing broadband or cable environments should track this vendor's advisories closely and prioritize firmware updates for deployed devices; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
48
Total CVEs
More Total CVEs than 98% of tracked vendors
3.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 94% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Rdkcentral over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 20, 2019
7 years ago
Most Recent CVE
Mar 2, 2026
144 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (48 CVEs).

48 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-6963HIGH
A heap-based buffer overflow in cosa_dhcpv4_dml.c in the RDK RDKB-20181217-1 CcspPandM module may allow attackers with login credentials to achieve remote code execution by craftin
Jun 20, 20198.828NONO
CVE-2024-20080CRITICAL
In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution
Jul 1, 20249.826NONO
CVE-2025-20747MEDIUM
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtaine
Nov 4, 20256.724NONO
CVE-2025-20696MEDIUM
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, wi
Aug 4, 20256.824NONO
CVE-2024-20104HIGH
In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User
Nov 4, 20248.424NONO
CVE-2024-20040HIGH
In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privilege
Apr 1, 20248.824NONO
CVE-2026-20435MEDIUM
In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the
Mar 2, 20264.623NONO
CVE-2025-20746MEDIUM
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtaine
Nov 4, 20256.723NONO
CVE-2025-20730MEDIUM
In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege if a malicious actor has already obtain
Nov 4, 20256.723NONO
CVE-2024-20089HIGH
In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User int
Sep 2, 20247.523NONO
View all 48 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products48 CVEs
79%
15%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local31 (64.6%)
Network7 (14.6%)
Unknown0 (0.0%)
Physical9 (18.8%)
Adjacent Network1 (2.1%)
Attack Complexity
Low46 (95.8%)
High2 (4.2%)
Unknown0 (0.0%)
User Interaction
None43 (89.6%)
Unknown0 (0.0%)
Required5 (10.4%)
Privileges Required
Low7 (14.6%)
High25 (52.1%)
None16 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (48 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rdkcentral.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rdkcentral — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rdkcentral's Products

View all 2 CNAs →

Top CWEs