VYPR
Unrated severityNVD Advisory· Published Jun 20, 2022· Updated Sep 17, 2024

Realtek USB FE/1GbE/2.5GbE/5GbE NIC Family - Buffer Overflow

CVE-2022-21742

Description

A buffer overflow in Realtek USB driver API allows an unauthenticated LAN attacker to cause a denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A buffer overflow in Realtek USB driver API allows an unauthenticated LAN attacker to cause a denial of service.

Vulnerability

The Realtek USB driver for the FE/1GbE/2.5GbE/5GbE NIC family contains a buffer overflow vulnerability in its API function due to insufficient parameter length verification. Affected versions include Windows 10 (10.28 to 10.39), Windows 8 (8.49 to 8.60), and Windows 7 (7.42 to 7.53) [1]. The vulnerability is reachable when the driver processes specially crafted input from the network.

Exploitation

An unauthenticated attacker on the same local area network (LAN) can exploit this vulnerability without any privileges or user interaction. By sending a maliciously crafted request to the vulnerable API function, the attacker triggers a buffer overflow, leading to service disruption [1].

Impact

Successful exploitation results in a denial of service (DoS) condition, impacting system availability. The CVSS vector (AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) indicates no impact on confidentiality or integrity, but a high impact on availability [1].

Mitigation

Realtek has released version v10.50 of the driver to address this vulnerability. Users should update to this version or later. No workarounds are documented in the available references [1]. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.