Vulnerabilities > CVE-2020-27302 - Out-of-bounds Write vulnerability in Realtek Rtl8195A Firmware and Rtl8710C Firmware

047910
CVSS 7.7 - HIGH
Attack vector
ADJACENT_NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
low complexity
realtek
CWE-787

Summary

A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "memcpy" function, when an attacker in Wi-Fi range sends a crafted "Encrypted GTK" value as part of the WPA2 4-way-handshake.

Vulnerable Configurations

Part Description Count
OS
Realtek
2
Hardware
Realtek
2

Common Weakness Enumeration (CWE)