CVE-2020-25853: High severity realtek rtl8195a firmware vulnerability
The function CheckMic() in the Realtek RTL8195A Wi-Fi Module prior to versions released in April 2020 (up to and excluding 2.08) does not validate the size parameter for an internal function, rtmd5hmacveneer() or rthmacsha1veneer(), resulting in a stack buffer over-read which can be exploited for denial of service. An attacker can impersonate an Access Point and attack a vulnerable Wi-Fi client, by injecting a crafted packet into the WPA2 handshake. The attacker does not need to know the network's PSK.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-25853?
CVE-2020-25853 is a vulnerability in the Realtek RTL8195A Wi-Fi Module that allows for a stack buffer over-read due to a lack of validation in the CheckMic() function.
How severe is CVE-2020-25853?
CVE-2020-25853 has a severity rating of 7.5, which is considered high.
How can CVE-2020-25853 be exploited?
CVE-2020-25853 can be exploited by an attacker to perform a stack buffer over-read.
What software versions are affected by CVE-2020-25853?
CVE-2020-25853 affects Realtek RTL8195A Wi-Fi Module firmware versions up to and excluding 2.08.
Is Realtek RTL8195A vulnerable to CVE-2020-25853?
No, the Realtek RTL8195A itself is not vulnerable to CVE-2020-25853.
Is there a fix available for CVE-2020-25853?
Yes, fixes for CVE-2020-25853 were released in versions of the Realtek RTL8195A Wi-Fi Module firmware starting from April 2020 (versions released after 2.08).
What is the Common Weakness Enumeration (CWE) for CVE-2020-25853?
CVE-2020-25853 is associated with CWE-125: Out-of-bounds Read and CWE-126: Buffer Over-read.