CVE-2019-18990: Realtek RTL8192ER Firmware

Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.

A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RTL8881AN 1.09 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an attacker to discern information or potentially modify data.

Affected products

  • Realtek RTL8192ER Firmware: version 2.10 only
  • Realtek RTL8196D Firmware: version 1.0.0 only
  • Realtek RTL8812AR Firmware: version 1.21ww only
  • Realtek RTL8881AN Firmware: version 1.09 only

Published 2020-09-30. Last modified 2026-06-17.