Rdk B
Vendor:
First CVE: May 15, 2023 · Active for 3 years
44
Total CVEs
More Total CVEs than 97% of tracked products
11.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Rdk B over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 15, 2023
3 years ago
Most Recent CVE
Mar 2, 2026
147 days ago
CVE Severity & Scoring
Rdk B44 CVEs
84%
9%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local31 (70.5%)
Network3 (6.8%)
Unknown0 (0.0%)
Physical9 (20.5%)
Adjacent Network1 (2.3%)
Attack Complexity
Low43 (97.7%)
High1 (2.3%)
Unknown0 (0.0%)
User Interaction
None39 (88.6%)
Unknown0 (0.0%)
Required5 (11.4%)
Privileges Required
Low3 (6.8%)
High25 (56.8%)
None16 (36.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (44 CVEs).
44 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-20080CRITICAL In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution | Jul 1, 2024 | 9.8 | 26 | NO | NO |
CVE-2025-20747MEDIUM In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtaine | Nov 4, 2025 | 6.7 | 24 | NO | NO |
CVE-2025-20696MEDIUM In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, wi | Aug 4, 2025 | 6.8 | 24 | NO | NO |
CVE-2024-20104HIGH In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User | Nov 4, 2024 | 8.4 | 24 | NO | NO |
CVE-2024-20040HIGH In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privilege | Apr 1, 2024 | 8.8 | 24 | NO | NO |
CVE-2026-20435MEDIUM In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the | Mar 2, 2026 | 4.6 | 23 | NO | NO |
CVE-2025-20746MEDIUM In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtaine | Nov 4, 2025 | 6.7 | 23 | NO | NO |
CVE-2025-20730MEDIUM In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege if a malicious actor has already obtain | Nov 4, 2025 | 6.7 | 23 | NO | NO |
CVE-2024-20089HIGH In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User int | Sep 2, 2024 | 7.5 | 23 | NO | NO |
CVE-2025-20722MEDIUM In gnss driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the Sys | Oct 14, 2025 | 5.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (44 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (44 CVEs).
Media Mentions
Signals from CVEs in this product scope (44 CVEs).
Top CNAs Publishing CVEs For Rdk B
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2024q1 | 16 | 6.4 | 0.1% | 0 | 0 |
| 2022q3 | 38 | 6.1 | 0.1% | 0 | 0 |