RDK Central develops the Reference Design Kit for Broadband (RDK-B), a modular firmware platform widely deployed across cable set-top boxes, gateways, and residential broadband devices. The vendor's vulnerability footprint, while concentrated in a narrowly scoped product line, carries outsized importance because firmware flaws in these edge devices can affect large populations of home networks and potentially serve as pivots into broader infrastructure. The exposure recurs through memory-safety and access-control weakness classes—out-of-bounds reads and writes, missing authorization checks, and improper exception handling—that are characteristic of C-based embedded codebases operating with minimal isolation. Defenders managing broadband or cable environments should track this vendor's advisories closely and prioritize firmware updates for deployed devices; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rdkcentral over time
Signals from CVEs in this vendor scope (48 CVEs).
48 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-6963HIGH A heap-based buffer overflow in cosa_dhcpv4_dml.c in the RDK RDKB-20181217-1 CcspPandM module may allow attackers with login credentials to achieve remote code execution by craftin | Jun 20, 2019 | 8.8 | 28 | NO | NO |
CVE-2024-20080CRITICAL In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution | Jul 1, 2024 | 9.8 | 26 | NO | NO |
CVE-2025-20747MEDIUM In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtaine | Nov 4, 2025 | 6.7 | 24 | NO | NO |
CVE-2025-20696MEDIUM In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, wi | Aug 4, 2025 | 6.8 | 24 | NO | NO |
CVE-2024-20104HIGH In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User | Nov 4, 2024 | 8.4 | 24 | NO | NO |
CVE-2024-20040HIGH In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privilege | Apr 1, 2024 | 8.8 | 24 | NO | NO |
CVE-2026-20435MEDIUM In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the | Mar 2, 2026 | 4.6 | 23 | NO | NO |
CVE-2025-20746MEDIUM In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtaine | Nov 4, 2025 | 6.7 | 23 | NO | NO |
CVE-2025-20730MEDIUM In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege if a malicious actor has already obtain | Nov 4, 2025 | 6.7 | 23 | NO | NO |
CVE-2024-20089HIGH In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User int | Sep 2, 2024 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (48 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rdkcentral.
Media articles that mention a CVE ID that affects a product developed by Rdkcentral — matched by CVE ID, not by vendor name.