Vulnerability index

Browse CVEs

68 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2022-40740 Realtek GPON router has insufficient filtering for special characters. A remote attacker authenticated as an administrator can exploit this vulnerabi… Usdk Mitigation only Fix from $1,9502023-01-03 MEDIUM 6.5 CVE-2022-32966 RTL8168FP-CG Dash remote management function has missing authorization. An unauthenticated attacker within the adjacent network can connect to DASH s… Rtl8111fp Cg Firmware after 5.0.23 Fix from $1,6002022-11-29 HIGH 7.5 CVE-2022-34326 In ambiot amb1_sdk (aka SDK for Ameba1) before 2022-06-20 on Realtek RTL8195AM devices before 284241d70308ff2519e40afd7b284ba892c730a3, the timer tas… Rtl8195am Firmware 2022-06-20+ Fix from $1,9502022-09-27 MEDIUM 6.5 CVE-2022-25635 Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for broadcast network packet length. An u… Bluetooth Mesh Software Development Kit after 4.17-4.17-20220127 Fix from $1,6002022-08-30 MEDIUM 6.5 CVE-2022-26527 Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the size of segmented packets’ refere… Bluetooth Mesh Software Development Kit after 4.17-4.17-20220127 Fix from $1,6002022-08-30 MEDIUM 6.5 CVE-2022-26528 Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the length of segmented packets’ shif… Bluetooth Mesh Software Development Kit after 4.17-4.17-20220127 Fix from $1,6002022-08-30 MEDIUM 6.5 CVE-2022-26529 Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for segmented packets’ link parameter. An… Bluetooth Mesh Software Development Kit after 4.17-4.17-20220127 Fix from $1,6002022-08-30 CRITICAL 9.8 CVE-2022-27255EPSS 37% In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows an attacker… Ecos Rsdk Firmware Mitigation only Fix from $2,3002022-08-01 HIGH 8.8 CVE-2022-29558 Realtek rtl819x-SDK before v3.6.1 allows command injection over the web interface. Rtl819x Software Development Kit 3.6.1+ Fix from $1,9502022-07-28 MEDIUM 6.5 CVE-2022-21742 Realtek USB driver has a buffer overflow vulnerability due to insufficient parameter length verification in the API function. An unauthenticated LAN … Rtl8156 Firmware 10.50+ Fix from $1,6002022-06-20 CRITICAL 9.8 CVE-2021-39306 A stack buffer overflow was discovered on Realtek RTL8195AM device before 2.0.10, it exists in the client code when an attacker sends a big size Auth… Rtl8195am Firmware 2.0.10+ Fix from $2,3002021-12-22 CRITICAL 9.8 CVE-2021-43573 A buffer overflow was discovered on Realtek RTL8195AM devices before 2.0.10. It exists in the client code when processing a malformed IE length of HT… Rtl8195am Firmware after 2.0.10 Fix from $2,3002021-11-11 HIGH 7.8 CVE-2021-36922 RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve unauthorized acces… Rtsupx Usb Utility Driver after 1.14.0.0 Fix from $1,9502021-11-02 HIGH 7.8 CVE-2021-36923 RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve unauthorized acces… Rtsupx Usb Utility Driver after 1.14.0.0 Fix from $1,9502021-11-02 HIGH 7.8 CVE-2021-36924 RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve a pool overflow (l… Rtsupx Usb Utility Driver after 1.14.0.0 Fix from $1,9502021-11-02 HIGH 7.8 CVE-2021-36925 RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve an arbitrary read … Rtsupx Usb Utility Driver after 1.14.0.0 Fix from $1,9502021-11-02 CRITICAL 9.8 CVE-2021-35393EPSS 70% Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usu… Rtl819x Jungle Software Development Kit after 3.4.14b Fix from $2,3002021-08-16 CRITICAL 9.8 CVE-2021-35394 KEVEPSS 100% Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The bina… Rtl819x Jungle Software Development Kit after 3.4.14b Fix from $2,3002021-08-16 CRITICAL 9.8 CVE-2021-35395 KEVEPSS 98% Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access p… Rtl819x Jungle Software Development Kit after 3.4.14b Fix from $2,3002021-08-16 HIGH 7.5 CVE-2021-35392EPSS 83% Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usu… Rtl819x Jungle Software Development Kit after 3.4.14b Fix from $1,9502021-08-16 MEDIUM 6.5 CVE-2021-32537 Realtek HAD contains a driver crashed vulnerability which allows local side attackers to send a special string to the kernel driver in a user’s mode.… Hda Driver after 9150 Fix from $1,6002021-07-07 HIGH 8.0 CVE-2020-27302 A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "memcpy" function, when an attac… Rtl8710c Firmware No fix yet Fix from $1,9502021-06-04 HIGH 8.0 CVE-2020-27301 A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "AES_UnWRAP" function, when an a… Rtl8710c Firmware No fix yet Fix from $1,9502021-06-04 HIGH 7.5 CVE-2020-23539 An issue was discovered in Realtek rtl8723de BLE Stack <= 4.1 that allows remote attackers to cause a Denial of Service via the interval field to the… Rtl8723de Firmware after 4.1 Fix from $1,9502021-04-08 CRITICAL 9.8 CVE-2021-27372 Realtek xPON RTL9601D SDK 1.9 stores passwords in plaintext which may allow attackers to possibly gain access to the device with root permissions via… Xpon Rtl9601d Software Development Kit Mitigation only Fix from $2,3002021-03-25 HIGH 8.1 CVE-2020-25855 The function AES_UnWRAP() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate … Rtl8195a Firmware 2.08+ Fix from $1,9502021-02-03 HIGH 8.1 CVE-2020-25856 The function DecWPA2KeyData() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not valid… Rtl8195a Firmware 2.08+ Fix from $1,9502021-02-03 HIGH 7.5 CVE-2020-25857 The function ClientEAPOLKeyRecvd() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not … Rtl8195a Firmware 2.08+ Fix from $1,9502021-02-03 HIGH 8.1 CVE-2020-25854 The function DecWPA2KeyData() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not valid… Rtl8195a Firmware 2.08+ Fix from $1,9502021-02-03 HIGH 7.5 CVE-2020-25853 The function CheckMic() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate th… Rtl8195a Firmware 2.08+ Fix from $1,9502021-02-03