VYPR

Rtl8195a Firmware

by Realtek

CVEs (7)

  • CVE-2020-25856HigFeb 3, 2021
    risk 0.53cvss 8.1epss 0.02

    The function DecWPA2KeyData() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for an rtl_memcpy() operation, resulting in a stack buffer overflow which can be exploited for remote code…

  • CVE-2020-25855HigFeb 3, 2021
    risk 0.53cvss 8.1epss 0.03

    The function AES_UnWRAP() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for a memcpy() operation, resulting in a stack buffer overflow which can be exploited for remote code execution…

  • CVE-2020-25854HigFeb 3, 2021
    risk 0.53cvss 8.1epss 0.03

    The function DecWPA2KeyData() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for an internal function, rt_arc4_crypt_veneer() or _AES_UnWRAP_veneer(), resulting in a stack buffer…

  • CVE-2020-27302HigJun 4, 2021
    risk 0.52cvss 8.0epss 0.02

    A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "memcpy" function, when an attacker in Wi-Fi range sends a crafted "Encrypted GTK" value as part of the WPA2 4-way-handshake.

  • CVE-2020-27301HigJun 4, 2021
    risk 0.52cvss 8.0epss 0.02

    A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "AES_UnWRAP" function, when an attacker in Wi-Fi range sends a crafted "Encrypted GTK" value as part of the WPA2 4-way-handshake.

  • CVE-2020-25857HigFeb 3, 2021
    risk 0.49cvss 7.5epss 0.01

    The function ClientEAPOLKeyRecvd() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for an rtl_memcpy() operation, resulting in a stack buffer overflow which can be exploited for denial…

  • CVE-2020-25853HigFeb 3, 2021
    risk 0.49cvss 7.5epss 0.01

    The function CheckMic() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for an internal function, _rt_md5_hmac_veneer() or _rt_hmac_sha1_veneer(), resulting in a stack buffer over-read…