CVE-2020-27301: Buffer Overflow
Published Jun 4, 2021
·Updated
A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "AESUnWRAP" function, when an attacker in Wi-Fi range sends a crafted "Encrypted GTK" value as part of the WPA2 4-way-handshake.
Affected Software
4 affected components
Realtek Rtl8710c Firmware
Realtek Rtl8710c
Realtek Rtl8195a Firmware
Realtek RTL8195A
Event History
Jun 4, 2021
CVE Published
via MITRE·12:24 PM
Data Sourced
via MITRE·12:24 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-27301.
2
What is the severity of CVE-2020-27301?
CVE-2020-27301 has a severity level of high (8).
3
Which devices are affected by CVE-2020-27301?
Realtek RTL8710c Firmware and Realtek RTL8195A Firmware are affected by CVE-2020-27301.
4
What is the impact of CVE-2020-27301?
CVE-2020-27301 can lead to remote code execution on affected devices.
5
How can CVE-2020-27301 be exploited?
CVE-2020-27301 can be exploited by an attacker in Wi-Fi range sending a crafted "Encrypted GTK" value as part of the WPA2 4-way-handshake.