CVE-2019-18990: Realtek RTL8192ER Firmware
Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.
A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RTL8881AN 1.09 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an attacker to discern information or potentially modify data.
Affected products
- Realtek RTL8192ER Firmware: version 2.10 only
- Realtek RTL8196D Firmware: version 1.0.0 only
- Realtek RTL8812AR Firmware: version 1.21ww only
- Realtek RTL8881AN Firmware: version 1.09 only
Published 2020-09-30. Last modified 2026-06-17.