ZeroHour

CVE-2019-18990

CVSS 3.1
5.4 medium
EPSS
<1%p53
Published
()
Modified
Description

A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RTL8881AN 1.09 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an attacker to discern information or potentially modify data.

Vendors
realtek
Products
rtl8812ar firmware, rtl8196d firmware, rtl8192er firmware, rtl8881an firmware
Weakness
CWE-290
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news