Записи Realtek
77 опубликованных записей вендора realtek.
Профиль для исследователя
- Попали в KEV
- 3 · 3,9 %
- С эксплойтом
- 4 · 5,2 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- 116 дн.
Повторяющиеся классы
- CWE-121 Stack-based Buffer Overflow16
- CWE-787 Out-of-bounds Write7
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')6
- CWE-122 Heap-based Buffer Overflow5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')5
- CWE-400 Uncontrolled Resource Consumption3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
77 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2014-8361Готовый эксплойт | The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploirealtek · realtek sdk | Критическая9,8 | KEV | 100,0 % | 1 мая 2015 г. |
99Срочно | CVE-2021-35394Готовый эксплойт | Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary.realtek · rtl819x jungle software development kit · CWE-78 | Критическая9,8 | KEV | 99,9 % | 16 авг. 2021 г. |
98Срочно | CVE-2021-35395Готовый эксплойт | Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure therealtek · rtl819x jungle software development kit | Критическая9,8 | KEV | 98,0 % | 16 авг. 2021 г. |
60На этой неделе | CVE-2021-35393Эксплойта нет | Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols.realtek · rtl819x jungle software development kit · CWE-787 | Критическая9,8 | — | 70,3 % | 16 авг. 2021 г. |
55В плане | CVE-2021-35392Proof of concept | Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols.realtek · rtl819x jungle software development kit · CWE-787 | Высокая7,5 | — | 83,2 % | 16 авг. 2021 г. |
50В плане | CVE-2022-27255Proof of concept | In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow.realtek · ecos rsdk firmware · CWE-20 | Критическая9,8 | — | 37,1 % | 1 авг. 2022 г. |
48В плане | CVE-2008-5664Готовый эксплойт | Stack-based buffer overflow in Realtek Media Player (aka Realtek Sound Manager, RtlRack, or rtlrack.exe) 1.15.0.0 allows remote attackers torealtek · realtek media player · CWE-119 | Критическая9,3 | — | 36,2 % | 18 дек. 2008 г. |
39Наблюдать | CVE-2021-27372Эксплойта нет | Realtek xPON RTL9601D SDK 1.9 stores passwords in plaintext which may allow attackers to possibly gain access to the device with root permisrealtek · xpon rtl9601d software development kit · CWE-522 | Критическая9,8 | — | 1,6 % | 25 мар. 2021 г. |
39Наблюдать | CVE-2021-39306Эксплойта нет | A stack buffer overflow was discovered on Realtek RTL8195AM device before 2.0.10, it exists in the client code when an attacker sends a big realtek · rtl8195am firmware · CWE-787 | Критическая9,8 | — | 1,3 % | 22 дек. 2021 г. |
39Наблюдать | CVE-2021-43573Эксплойта нет | A buffer overflow was discovered on Realtek RTL8195AM devices before 2.0.10.realtek · rtl8195am firmware · CWE-120 | Критическая9,8 | — | 1,1 % | 11 нояб. 2021 г. |
35Наблюдать | CVE-2022-29558Эксплойта нет | Realtek rtl819x-SDK before v3.6.1 allows command injection over the web interface.realtek · rtl819x software development kit · CWE-77 | Высокая8,8 | — | 1,3 % | 28 июл. 2022 г. |
35Наблюдать | CVE-2024-40431Proof of concept | A lack of input validation in Realtek SD card reader driver before 10.0.26100.21374 through the implementation of the IOCTL_SCSI_PASS_THROUG | Высокая8,8 | — | 1,3 % | 23 окт. 2024 г. |
35Наблюдать | CVE-2020-12773Эксплойта нет | Realtek ADSL/PON Modem SoC - Security Misconfigurationrealtek · adsl router soc firmware | Высокая8,8 | — | 1,2 % | 8 июн. 2020 г. |
35Наблюдать | CVE-2023-47677Эксплойта нет | A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11.realtek · rtl819x jungle software development kit · CWE-352 | Высокая8,8 | — | 0,4 % | 8 июл. 2024 г. |
35Наблюдать | CVE-2025-8299Эксплойта нет | Realtek rtl81xx SDK Wi-Fi Driver MgntActSet_TEREDO_SET_RS_PACKET Heap-based Buffer Overflow Local Privilege Escalation Vulnerabilityrealtek · wi-fi usb driver · CWE-122 | Высокая8,8 | — | 0,2 % | 2 сент. 2025 г. |
35Наблюдать | CVE-2025-8300Эксплойта нет | Realtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation Vulnerabilityrealtek · wi-fi usb driver · CWE-122 | Высокая8,8 | — | 0,2 % | 2 сент. 2025 г. |
35Наблюдать | CVE-2025-8302Эксплойта нет | Realtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation Vulnerabilityrealtek · wi-fi usb driver · CWE-122 | Высокая8,8 | — | 0,2 % | 2 сент. 2025 г. |
33Наблюдать | CVE-2019-19822Proof of concept | A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the corealtek · rtk 11n ap firmware · CWE-306 | Высокая7,5 | — | 8,7 % | 27 янв. 2020 г. |
33Наблюдать | CVE-2020-25855Эксплойта нет | The function AES_UnWRAP() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not realtek · rtl8195a firmware · CWE-121 | Высокая8,1 | — | 2,6 % | 3 февр. 2021 г. |
33Наблюдать | CVE-2020-25854Эксплойта нет | The function DecWPA2KeyData() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does realtek · rtl8195a firmware · CWE-121 | Высокая8,1 | — | 2,6 % | 3 февр. 2021 г. |
33Наблюдать | CVE-2020-25856Эксплойта нет | The function DecWPA2KeyData() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does realtek · rtl8195a firmware · CWE-121 | Высокая8,1 | — | 2,2 % | 3 февр. 2021 г. |
33Наблюдать | CVE-2020-27302Эксплойта нет | A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "memcpy" function, whenrealtek · rtl8710c firmware · CWE-787 | Высокая8,0 | — | 2,0 % | 4 июн. 2021 г. |
33Наблюдать | CVE-2020-27301Proof of concept | A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "AES_UnWRAP" function, realtek · rtl8710c firmware · CWE-787 | Высокая8,0 | — | 2,0 % | 4 июн. 2021 г. |
33Наблюдать | CVE-2024-33224Эксплойта нет | An issue in the component rtkio64.sys of Realtek Semiconductor Corp Realtek lO Driver v1.008.0823.2017 allows attackers to escalate privilegCWE-269 | Высокая8,4 | — | 0,2 % | 22 мая 2024 г. |
32Наблюдать | CVE-2019-19823Proof of concept | A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords realtek · rtk 11n ap firmware · CWE-522 | Высокая7,5 | — | 6,4 % | 27 янв. 2020 г. |
- CVE-2014-836199Срочно
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploi
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %realtek · realtek sdk1 мая 2015 г.
- CVE-2021-3539499Срочно
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %realtek · rtl819x jungle software development kit16 авг. 2021 г.
- CVE-2021-3539598Срочно
Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %realtek · rtl819x jungle software development kit16 авг. 2021 г.
- CVE-2021-3539360На этой неделе
Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols.
КритическаяCVSS 9,8Эксплойта нетEPSS 70 %realtek · rtl819x jungle software development kit16 авг. 2021 г.
- CVE-2021-3539255В плане
Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols.
ВысокаяCVSS 7,5Proof of conceptEPSS 83 %realtek · rtl819x jungle software development kit16 авг. 2021 г.
- CVE-2022-2725550В плане
In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow.
КритическаяCVSS 9,8Proof of conceptEPSS 37 %realtek · ecos rsdk firmware1 авг. 2022 г.
- CVE-2008-566448В плане
Stack-based buffer overflow in Realtek Media Player (aka Realtek Sound Manager, RtlRack, or rtlrack.exe) 1.15.0.0 allows remote attackers to
КритическаяCVSS 9,3Готовый эксплойтEPSS 36 %realtek · realtek media player18 дек. 2008 г.
- CVE-2021-2737239Наблюдать
Realtek xPON RTL9601D SDK 1.9 stores passwords in plaintext which may allow attackers to possibly gain access to the device with root permis
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %realtek · xpon rtl9601d software development kit25 мар. 2021 г.
- CVE-2021-3930639Наблюдать
A stack buffer overflow was discovered on Realtek RTL8195AM device before 2.0.10, it exists in the client code when an attacker sends a big
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %realtek · rtl8195am firmware22 дек. 2021 г.
- CVE-2021-4357339Наблюдать
A buffer overflow was discovered on Realtek RTL8195AM devices before 2.0.10.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %realtek · rtl8195am firmware11 нояб. 2021 г.
- CVE-2022-2955835Наблюдать
Realtek rtl819x-SDK before v3.6.1 allows command injection over the web interface.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %realtek · rtl819x software development kit28 июл. 2022 г.
- CVE-2024-4043135Наблюдать
A lack of input validation in Realtek SD card reader driver before 10.0.26100.21374 through the implementation of the IOCTL_SCSI_PASS_THROUG
ВысокаяCVSS 8,8Proof of conceptEPSS 1 %23 окт. 2024 г.
- CVE-2020-1277335Наблюдать
Realtek ADSL/PON Modem SoC - Security Misconfiguration
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %realtek · adsl router soc firmware8 июн. 2020 г.
- CVE-2023-4767735Наблюдать
A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %realtek · rtl819x jungle software development kit8 июл. 2024 г.
- CVE-2025-829935Наблюдать
Realtek rtl81xx SDK Wi-Fi Driver MgntActSet_TEREDO_SET_RS_PACKET Heap-based Buffer Overflow Local Privilege Escalation Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %realtek · wi-fi usb driver2 сент. 2025 г.
- CVE-2025-830035Наблюдать
Realtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %realtek · wi-fi usb driver2 сент. 2025 г.
- CVE-2025-830235Наблюдать
Realtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %realtek · wi-fi usb driver2 сент. 2025 г.
- CVE-2019-1982233Наблюдать
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the co
ВысокаяCVSS 7,5Proof of conceptEPSS 9 %realtek · rtk 11n ap firmware27 янв. 2020 г.
- CVE-2020-2585533Наблюдать
The function AES_UnWRAP() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not
ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %realtek · rtl8195a firmware3 февр. 2021 г.
- CVE-2020-2585433Наблюдать
The function DecWPA2KeyData() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does
ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %realtek · rtl8195a firmware3 февр. 2021 г.
- CVE-2020-2585633Наблюдать
The function DecWPA2KeyData() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %realtek · rtl8195a firmware3 февр. 2021 г.
- CVE-2020-2730233Наблюдать
A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "memcpy" function, when
ВысокаяCVSS 8,0Эксплойта нетEPSS 2 %realtek · rtl8710c firmware4 июн. 2021 г.
- CVE-2020-2730133Наблюдать
A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "AES_UnWRAP" function,
ВысокаяCVSS 8,0Proof of conceptEPSS 2 %realtek · rtl8710c firmware4 июн. 2021 г.
- CVE-2024-3322433Наблюдать
An issue in the component rtkio64.sys of Realtek Semiconductor Corp Realtek lO Driver v1.008.0823.2017 allows attackers to escalate privileg
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %22 мая 2024 г.
- CVE-2019-1982332Наблюдать
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords
ВысокаяCVSS 7,5Proof of conceptEPSS 6 %realtek · rtk 11n ap firmware27 янв. 2020 г.