CVE-2020-27301: Realtek RTL8195A Firmware
High severity, CVSS 8.0. EPSS: 2% chance of exploitation in the next 30 days.
A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "AES_UnWRAP" function, when an attacker in Wi-Fi range sends a crafted "Encrypted GTK" value as part of the WPA2 4-way-handshake.
Affected products
- Realtek RTL8195A Firmware: affected versions not specified
- Realtek RTL8710C Firmware: affected versions not specified
Published 2021-06-04. Last modified 2026-06-17.