Critical severity9.8NVD Advisory· Published Aug 1, 2022· Updated Jun 17, 2026
CVE-2022-27255
CVE-2022-27255
Description
In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows an attacker to remotely execute code without authentication via a crafted SIP packet that contains malicious SDP data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:o:realtek:ecos_msdk_firmware:4.9.4p1:*:*:*:*:*:*:*
- cpe:2.3:o:realtek:ecos_rsdk_firmware:1.5.7p1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- forum.defcon.org/node/241835nvdThird Party Advisory
- www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2022-27255.pdfnvdVendor Advisory
News mentions
0No linked articles in our index yet.