CVE-2020-27302: Buffer Overflow
A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "memcpy" function, when an attacker in Wi-Fi range sends a crafted "Encrypted GTK" value as part of the WPA2 4-way-handshake.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-27302?
CVE-2020-27302 is a stack buffer overflow vulnerability in Realtek RTL8710 (and other Ameba-based devices) that can lead to remote code execution.
How does CVE-2020-27302 work?
CVE-2020-27302 occurs when an attacker in Wi-Fi range sends a crafted "Encrypted GTK" value as part of the WPA2 4-way-handshake, which triggers a stack buffer overflow in the "memcpy" function.
Which software versions are affected by CVE-2020-27302?
The Realtek RTL8710c Firmware and the Realtek RTL8195A Firmware are affected by CVE-2020-27302.
What is the severity of CVE-2020-27302?
CVE-2020-27302 has a severity rating of high.
Where can I find more information about CVE-2020-27302?
You can find more information about CVE-2020-27302 at the following link: [https://www.vdoo.com/blog/realtek-wifi-vulnerabilities-zero-day](https://www.vdoo.com/blog/realtek-wifi-vulnerabilities-zero-day).