Stack Buffer Overflow Vulnerability in Realtek RTL8710 Devices
CVE-2020-27301

8HIGH

Key Information:

Vendor

Realtek

Vendor
CVE Published:
4 June 2021

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2020-27301?

A stack buffer overflow vulnerability exists in the Realtek RTL8710 and other Ameba-based devices. This flaw can be exploited by an attacker within Wi-Fi range who sends a specially crafted 'Encrypted GTK' value during the WPA2 4-way handshake. Successful exploitation of this vulnerability may allow the attacker to execute arbitrary code remotely, posing a serious threat to device integrity and security.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-27301 : Stack Buffer Overflow Vulnerability in Realtek RTL8710 Devices