Known Vulnerabilities for products from Realtek

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Realtek".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Additional devices specifications by Realtek can be found at device.report : Realtek

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2022-40740 json Realtek GPON router has insufficient filtering for special characters. A remote attacker authenticated as an administrator ca... 7.2 - HIGH 2023-01-03 2023-07-10
CVE-2022-34326 json In ambiot amb1_sdk (aka SDK for Ameba1) before 2022-06-20 on Realtek RTL8195AM devices before 284241d70308ff2519e40afd7b284ba... 7.5 - HIGH 2022-09-27 2022-10-15
CVE-2022-32967 json RTL8111EP-CG/RTL8111FP-CG DASH function has hard-coded password. An unauthenticated physical attacker can use the hard-coded ... 2.1 - LOW 2022-11-29 2022-11-30
CVE-2022-32966 json RTL8168FP-CG Dash remote management function has missing authorization. An unauthenticated attacker within the adjacent netwo... 6.5 - MEDIUM 2022-11-29 2022-11-30
CVE-2022-29558 json Realtek rtl819x-SDK before v3.6.1 allows command injection over the web interface. 8.8 - HIGH 2022-07-28 2022-08-04
CVE-2022-27255 json In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow.... 9.8 - CRITICAL 2022-08-01 2022-09-30
CVE-2022-26529 json Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for segmented pac... 6.5 - MEDIUM 2022-08-30 2022-09-02
CVE-2022-26528 json Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the length of... 6.5 - MEDIUM 2022-08-30 2022-09-02
CVE-2022-26527 json Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the size of s... 6.5 - MEDIUM 2022-08-30 2022-09-02
CVE-2022-25635 json Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for broadcast net... 6.5 - MEDIUM 2022-08-30 2022-09-01
CVE-2022-21742 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 6.5 - MEDIUM 2022-06-20 2022-07-05
CVE-2021-43573 json A buffer overflow was discovered on Realtek RTL8195AM devices before 2.0.10. It exists in the client code when processing a m... 9.8 - CRITICAL 2021-11-11 2021-12-21
CVE-2021-39306 json A stack buffer overflow was discovered on Realtek RTL8195AM device before 2.0.10, it exists in the client code when an attack... 9.8 - CRITICAL 2021-12-22 2022-01-04
CVE-2021-36925 json RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to ac... 7.8 - HIGH 2021-11-02 2021-11-08
CVE-2021-36924 json RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to ac... 7.8 - HIGH 2021-11-02 2022-07-12
CVE-2021-36923 json RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to ac... 7.8 - HIGH 2021-11-02 2022-07-12
CVE-2021-36922 json RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to ac... 7.8 - HIGH 2021-11-02 2022-07-12
CVE-2021-35395 json Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used t... 9.8 - CRITICAL 2021-08-16 2023-08-08
CVE-2021-35394 json Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDP... 9.8 - CRITICAL 2021-08-16 2023-08-08
CVE-2021-35393 json Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP prot... 9.8 - CRITICAL 2021-08-16 2021-08-26

Known software with vulnerabilities from Realtek

Type Vendor Product Version
Operating
System
RealtekAdsl Router Soc Firmware-
ApplicationRealtekNdis10.1.505.2015
ApplicationRealtekRealtek Ac97 Audio5.18
ApplicationRealtekRealtek Sdk-
HardwareRealtekRtk 11n Ap-
Operating
System
RealtekRtk 11n Ap Firmware2019-12-12
HardwareRealtekRtl8192er-
Operating
System
RealtekRtl8192er Firmware2.10
HardwareRealtekRtl8195am-
Operating
System
RealtekRtl8195am Firmware2.0.6
HardwareRealtekRtl8196d-
Operating
System
RealtekRtl8196d Firmware1.0.0
HardwareRealtekRtl8710af-
Operating
System
RealtekRtl8710af Firmware2.0.6
HardwareRealtekRtl8711af-
Operating
System
RealtekRtl8711af Firmware2.0.6
HardwareRealtekRtl8711am-
Operating
System
RealtekRtl8711am Firmware2.0.6
HardwareRealtekRtl8812ar-
Operating
System
RealtekRtl8812ar Firmware1.21ww