Vulnerability index

Browse CVEs

68 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Usdk HIGH 7.2
CVE-2022-40740

Realtek GPON router has insufficient filtering for special characters. A remote attacker authenticated as an administrator can exploit this vulnerabi…

Mitigation only
Fix from $1,950 2023-01-03
Rtl8111fp Cg Firmware MEDIUM 6.5
CVE-2022-32966

RTL8168FP-CG Dash remote management function has missing authorization. An unauthenticated attacker within the adjacent network can connect to DASH s…

Fix: after 5.0.23
Fix from $1,600 2022-11-29
Rtl8195am Firmware HIGH 7.5
CVE-2022-34326

In ambiot amb1_sdk (aka SDK for Ameba1) before 2022-06-20 on Realtek RTL8195AM devices before 284241d70308ff2519e40afd7b284ba892c730a3, the timer tas…

Fix: 2022-06-20+
Fix from $1,950 2022-09-27
Bluetooth Mesh Software Development Kit MEDIUM 6.5
CVE-2022-25635

Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for broadcast network packet length. An u…

Fix: after 4.17-4.17-20220127
Fix from $1,600 2022-08-30
Bluetooth Mesh Software Development Kit MEDIUM 6.5
CVE-2022-26527

Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the size of segmented packets’ refere…

Fix: after 4.17-4.17-20220127
Fix from $1,600 2022-08-30
Bluetooth Mesh Software Development Kit MEDIUM 6.5
CVE-2022-26528

Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the length of segmented packets’ shif…

Fix: after 4.17-4.17-20220127
Fix from $1,600 2022-08-30
Bluetooth Mesh Software Development Kit MEDIUM 6.5
CVE-2022-26529

Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for segmented packets’ link parameter. An…

Fix: after 4.17-4.17-20220127
Fix from $1,600 2022-08-30
Ecos Rsdk Firmware CRITICAL 9.8
CVE-2022-27255EPSS 37%

In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows an attacker…

Mitigation only
Fix from $2,300 2022-08-01
Rtl819x Software Development Kit HIGH 8.8
CVE-2022-29558

Realtek rtl819x-SDK before v3.6.1 allows command injection over the web interface.

Fix: 3.6.1+
Fix from $1,950 2022-07-28
Rtl8156 Firmware MEDIUM 6.5
CVE-2022-21742

Realtek USB driver has a buffer overflow vulnerability due to insufficient parameter length verification in the API function. An unauthenticated LAN …

Fix: 10.50+
Fix from $1,600 2022-06-20
Rtl8195am Firmware CRITICAL 9.8
CVE-2021-39306

A stack buffer overflow was discovered on Realtek RTL8195AM device before 2.0.10, it exists in the client code when an attacker sends a big size Auth…

Fix: 2.0.10+
Fix from $2,300 2021-12-22
Rtl8195am Firmware CRITICAL 9.8
CVE-2021-43573

A buffer overflow was discovered on Realtek RTL8195AM devices before 2.0.10. It exists in the client code when processing a malformed IE length of HT…

Fix: after 2.0.10
Fix from $2,300 2021-11-11
Rtsupx Usb Utility Driver HIGH 7.8
CVE-2021-36922

RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve unauthorized acces…

Fix: after 1.14.0.0
Fix from $1,950 2021-11-02
Rtsupx Usb Utility Driver HIGH 7.8
CVE-2021-36923

RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve unauthorized acces…

Fix: after 1.14.0.0
Fix from $1,950 2021-11-02
Rtsupx Usb Utility Driver HIGH 7.8
CVE-2021-36924

RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve a pool overflow (l…

Fix: after 1.14.0.0
Fix from $1,950 2021-11-02
Rtsupx Usb Utility Driver HIGH 7.8
CVE-2021-36925

RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve an arbitrary read …

Fix: after 1.14.0.0
Fix from $1,950 2021-11-02
Rtl819x Jungle Software Development Kit CRITICAL 9.8
CVE-2021-35393EPSS 70%

Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usu…

Fix: after 3.4.14b
Fix from $2,300 2021-08-16
Rtl819x Jungle Software Development Kit CRITICAL 9.8
CVE-2021-35394 KEVEPSS 100%

Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The bina…

Fix: after 3.4.14b
Fix from $2,300 2021-08-16
Rtl819x Jungle Software Development Kit CRITICAL 9.8
CVE-2021-35395 KEVEPSS 98%

Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access p…

Fix: after 3.4.14b
Fix from $2,300 2021-08-16
Rtl819x Jungle Software Development Kit HIGH 7.5
CVE-2021-35392EPSS 83%

Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usu…

Fix: after 3.4.14b
Fix from $1,950 2021-08-16
Hda Driver MEDIUM 6.5
CVE-2021-32537

Realtek HAD contains a driver crashed vulnerability which allows local side attackers to send a special string to the kernel driver in a user’s mode.…

Fix: after 9150
Fix from $1,600 2021-07-07
Rtl8710c Firmware HIGH 8.0
CVE-2020-27302

A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "memcpy" function, when an attac…

No fix yet
Fix from $1,950 2021-06-04
Rtl8710c Firmware HIGH 8.0
CVE-2020-27301

A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "AES_UnWRAP" function, when an a…

No fix yet
Fix from $1,950 2021-06-04
Rtl8723de Firmware HIGH 7.5
CVE-2020-23539

An issue was discovered in Realtek rtl8723de BLE Stack <= 4.1 that allows remote attackers to cause a Denial of Service via the interval field to the…

Fix: after 4.1
Fix from $1,950 2021-04-08
Xpon Rtl9601d Software Development Kit CRITICAL 9.8
CVE-2021-27372

Realtek xPON RTL9601D SDK 1.9 stores passwords in plaintext which may allow attackers to possibly gain access to the device with root permissions via…

Mitigation only
Fix from $2,300 2021-03-25
Rtl8195a Firmware HIGH 8.1
CVE-2020-25855

The function AES_UnWRAP() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate …

Fix: 2.08+
Fix from $1,950 2021-02-03
Rtl8195a Firmware HIGH 8.1
CVE-2020-25856

The function DecWPA2KeyData() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not valid…

Fix: 2.08+
Fix from $1,950 2021-02-03
Rtl8195a Firmware HIGH 7.5
CVE-2020-25857

The function ClientEAPOLKeyRecvd() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not …

Fix: 2.08+
Fix from $1,950 2021-02-03
Rtl8195a Firmware HIGH 8.1
CVE-2020-25854

The function DecWPA2KeyData() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not valid…

Fix: 2.08+
Fix from $1,950 2021-02-03
Rtl8195a Firmware HIGH 7.5
CVE-2020-25853

The function CheckMic() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate th…

Fix: 2.08+
Fix from $1,950 2021-02-03