Vulnerability Description
A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "AES_UnWRAP" function, when an attacker in Wi-Fi range sends a crafted "Encrypted GTK" value as part of the WPA2 4-way-handshake.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Realtek | Rtl8710C Firmware | - |
| Realtek | Rtl8710C | - |
| Realtek | Rtl8195A Firmware | - |
| Realtek | Rtl8195A | - |
Related Weaknesses (CWE)
References
- https://www.vdoo.com/blog/realtek-wifi-vulnerabilities-zero-dayExploitThird Party Advisory
- https://www.vdoo.com/blog/realtek-wifi-vulnerabilities-zero-dayExploitThird Party Advisory
FAQ
What is CVE-2020-27301?
CVE-2020-27301 is a vulnerability with a CVSS score of 8.0 (HIGH). A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "AES_UnWRAP" function, when an attacker in Wi-Fi range sends a crafted "Encrypted G...
How severe is CVE-2020-27301?
CVE-2020-27301 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27301?
Check the references section above for vendor advisories and patch information. Affected products include: Realtek Rtl8710C Firmware, Realtek Rtl8710C, Realtek Rtl8195A Firmware, Realtek Rtl8195A.