ZeroHour

Vulnerabilities

70 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-8302
+4 in the same advisory: …8300 …8299 …8301 …8298
Realtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation Vulnerability.

Realtek rtl81xx SDK Wi-Fi Driver rtwlanu Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Realtek rtl81xx SDK Wi-Fi driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the N6CSet_DOT11_CIPHER_DEFAULT_KEY function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-26553.

NVD description · AI analysis pending
8.8
group max
<1%
  • realtek wi-fi usb driver
CVE-2025-44526
Realtek RTL8762EKF-EVB RTL8762E SDK V1.4.0 was discovered to utilize insufficient permission checks on critical fields within Bluetooth Low Energy (BLE) data pa

Realtek RTL8762EKF-EVB RTL8762E SDK V1.4.0 was discovered to utilize insufficient permission checks on critical fields within Bluetooth Low Energy (BLE) data packets. This issue allows attackers to cause a Denial of Service (DoS) via a crafted LL_Length_Req packet.

NVD description · AI analysis pending
6.5<1% PoC
  • realtek rtl8762e software development kit
CVE-2025-44531
An issue in Realtek RTL8762EKF-EVB RTL8762E SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted before a pairing public key is

An issue in Realtek RTL8762EKF-EVB RTL8762E SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted before a pairing public key is received during a Bluetooth connection attempt.

NVD description · AI analysis pending
7.5<1% PoC
  • realtek rtl8762e software development kit
CVE-2023-47677
A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11.

A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network request can lead to CSRF. An attacker can send an HTTP request to trigger this vulnerability.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • realtek rtl819x jungle software development kit
  • realtek wbr-6013 firmware
CVE-2022-25480
+3 in the same advisory: …25478 …25479 …25477
Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) befo

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows writing to kernel memory beyond the SystemBuffer of the IRP.

NVD description · AI analysis pending
7.8
group max
<1%
  • realtek rtsper
  • realtek rtsuer
CVE-2020-26652
An issue was discovered in function nl80211_send_chandef in rtl8812au v5.6.4.2 allows attackers to cause a denial of service.

An issue was discovered in function nl80211_send_chandef in rtl8812au v5.6.4.2 allows attackers to cause a denial of service.

NVD description · AI analysis pending
7.5<1% PoC
  • realtek rtl8812au firmware
CVE-2022-40740
Realtek GPON router has insufficient filtering for special characters.

Realtek GPON router has insufficient filtering for special characters. A remote attacker authenticated as an administrator can exploit this vulnerability to perform command injection attacks, to execute arbitrary system command, manipulate system or disrupt service.

NVD description · AI analysis pending
7.21%
  • realtek usdk
  • realtek xpon software development kit
CVE-2022-32967
RTL8111EP-CG/RTL8111FP-CG DASH function has hard-coded password.

RTL8111EP-CG/RTL8111FP-CG DASH function has hard-coded password. An unauthenticated physical attacker can use the hard-coded default password during system reboot triggered by other user, to acquire partial system information such as serial number and server information.

NVD description · AI analysis pending
2.1<1%
  • realtek rtl8111ep-cg firmware
  • realtek rtl8111fp-cg firmware
CVE-2022-32966
RTL8168FP-CG Dash remote management function has missing authorization.

RTL8168FP-CG Dash remote management function has missing authorization. An unauthenticated attacker within the adjacent network can connect to DASH service port to disrupt service.

NVD description · AI analysis pending
6.5<1%
  • realtek rtl8111fp-cg firmware
CVE-2022-34326
In ambiot amb1_sdk (aka SDK for Ameba1) before 2022-06-20 on Realtek RTL8195AM devices before 284241d70308ff2519e40afd7b284ba892c730a3, the timer task and RX ta

In ambiot amb1_sdk (aka SDK for Ameba1) before 2022-06-20 on Realtek RTL8195AM devices before 284241d70308ff2519e40afd7b284ba892c730a3, the timer task and RX task would be locked when there are frequent and continuous Wi-Fi connection (with four-way handshake) failures in Soft AP mode.

NVD description · AI analysis pending
7.5<1%
  • realtek rtl8195am firmware
CVE-2022-26529
+3 in the same advisory: …26528 …26527 …25635
Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for segmented packets’ link parameter.

Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for segmented packets’ link parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and disrupt service.

NVD description · AI analysis pending
6.5<1%
  • realtek bluetooth mesh software development kit
CVE-2022-27255
In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow.

In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows an attacker to remotely execute code without authentication via a crafted SIP packet that contains malicious SDP data.

NVD description · AI analysis pending
9.837%
  • realtek ecos rsdk firmware
  • realtek ecos msdk firmware
CVE-2022-29558
Realtek rtl819x-SDK before v3.6.1 allows command injection over the web interface.

Realtek rtl819x-SDK before v3.6.1 allows command injection over the web interface.

NVD description · AI analysis pending
8.81%
  • realtek rtl819x software development kit
CVE-2022-21742
Realtek USB driver has a buffer overflow vulnerability due to insufficient parameter length verification in the API function.

Realtek USB driver has a buffer overflow vulnerability due to insufficient parameter length verification in the API function. An unauthenticated LAN attacker can exploit this vulnerability to disrupt services.

NVD description · AI analysis pending
6.5<1%
  • realtek rtl8156 firmware
  • realtek rtl8156b firmware
  • realtek rtl8153 firmware
  • +1 more
CVE-2021-39306
A stack buffer overflow was discovered on Realtek RTL8195AM device before 2.0.10, it exists in the client code when an attacker sends a big size Authentication

A stack buffer overflow was discovered on Realtek RTL8195AM device before 2.0.10, it exists in the client code when an attacker sends a big size Authentication challenge text in WEP security.

NVD description · AI analysis pending
9.81%
  • realtek rtl8195am firmware
CVE-2021-43573
A buffer overflow was discovered on Realtek RTL8195AM devices before 2.0.10.

A buffer overflow was discovered on Realtek RTL8195AM devices before 2.0.10. It exists in the client code when processing a malformed IE length of HT capability information in the Beacon and Association response frame.

NVD description · AI analysis pending
9.81%
  • realtek rtl8195am firmware
CVE-2021-36925
+3 in the same advisory: …36923 …36922 …36924
RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve an arbitrary read or write op

RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve an arbitrary read or write operation from/to physical memory (leading to Escalation of Privileges, Denial of Service, Code Execution, and Information Disclosure) via a crafted Device IO Control packet to a device.

NVD description · AI analysis pending
7.8<1%
  • realtek rtsupx usb utility driver
CVE-2021-35395
Multiple Stack Buffer Overflows and Command Injection in Realtek Jungle SDK Web Server

The Realtek Jungle SDK (v2.x up to v3.4.14B) ships an HTTP management web server, in both Go-Ahead ('webs') and Boa ('boa') variants, containing multiple stack buffer overflows in form handlers such as formRebootCheck, formWsc, formWlanMultipleAP, formWlSiteSurvey and formStaticDHCP, plus arbitrary command execution/injection flaws in formSysCmd and formWsc. An unauthenticated attacker triggers these by sending crafted HTTP requests with oversized submit-url, ifname, hostname or peerPin parameters, or by injecting commands via the sysCmd or peerPin parameters. Successful exploitation yields arbitrary code execution on the device, typically giving the attacker full control of the affected router, access point or IoT device. Any device whose vendor embedded the affected SDK is exposed, with public reporting linking the flaws to roughly 65 downstream vendors and nearly a million internet-visible devices. Exploitation is confirmed in the wild: the issue is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), and researchers observed Mirai botnet variants and other attackers compromising Realtek-based devices; ransomware use is unknown.

Do: Apply firmware updates from your device vendor incorporating a patched Realtek SDK (newer than v3.4.14B), per CISA's required action; since vendors ship modified builds, confirm with the manufacturer that your model is fixed. Until patched, disable remote/web-based administration or restrict the management interface (WAN-facing HTTP) with a firewall so it is not internet-exposed. Defenders should also monitor Realtek-based devices for botnet-style activity (e.g., Mirai-variant traffic), as a public PoC/advisory from IoT Inspector is available and exploitation is ongoing.

9.898% KEV PoC
  • Realtek RTL819x Jungle SDK (Realtek AP-Router SDK) HTTP web server - both Go-Ahead 'webs' and Boa 'boa' management interfaces v2.x up to v3.4.14B
  • Routers, access points and other devices built on the Realtek Jungle SDK web server firmware builds shipping the affected SDK (vendor-specific; check with your device manufacturer)
mass≈1,000,000 internet-exposed devices (public scans reported nearly a million Realtek-based devices)
CVE-2021-35394
Remote Code Execution via Memory Corruption in Realtek Jungle SDK

Realtek's Jungle SDK, a software development kit used to build firmware for a wide range of consumer and small-office networking devices (most notably routers), contains multiple memory corruption vulnerabilities that can be triggered remotely over the network; public disclosure tied the flaws to unauthenticated network-facing components bundled with the SDK, such as its UPnP and DHCP handling. An attacker who sends crafted packets to a vulnerable device can corrupt memory and, per the associated weakness types (CWE-78 command injection, CWE-138 improper neutralization), end up executing arbitrary code or operating-system commands with the privileges of the vulnerable service, effectively taking over the device. Because the SDK is licensed into many vendors' products rather than sold as a standalone application, exposure spans numerous router and embedded-device vendors, and end users may not even know their device relies on it. Exact affected SDK version ranges and per-vendor firmware lists were not specified in the available data, so defenders should rely on the latest vendor advisories. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2021-12-10, indicating confirmed exploitation in the wild; ransomware use is unknown and no public proof-of-concept is flagged in the available data.

Do: Per CISA's required action, apply firmware updates per your device vendor's instructions, since patches are distributed by the vendors that build on the SDK rather than by Realtek directly. Identify whether your router or embedded device uses Realtek Jungle SDK-based firmware (check the vendor's model/advisory pages) and prioritize updating internet-facing devices. Where patched firmware is not yet available, restrict direct internet exposure (firewall the WAN side) and disable or limit UPnP/DHCP-related exposed services if the vendor supports doing so, while monitoring vendor advisories.

9.8100% KEV PoC
  • Realtek Jungle Software Development Kit (SDK)
mass≈ millions of devices (SDK embedded in consumer router/IoT firmware across many vendors; at least ~100,000 likely internet-exposed)