Vulnerability Intelligence Report
CVE-2020-9395
An issue was discovered on Realtek RTL8195AM, RTL8711AM, RTL8711AF, and RTL8710AF devices before 2.0.6. A stack-based buffer overflow exists in the client code that takes care of WPA2's 4-way-handshake via a malformed EAPOL-Key packet with a long keydata buffer.
No Active Exploit Signals
CVSS Base Score
8.0
HIGH
EPSS Probability:0.78%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| realtek | rtl8711af_firmware | all |
| realtek | rtl8711af | all |
| realtek | rtl8711am_firmware | all |
| realtek | rtl8711am | all |
| realtek | rtl8195am_firmware | all |
| realtek | rtl8195am | all |
| realtek | rtl8710af_firmware | all |
| realtek | rtl8710af | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.778%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2020-02-25T00:00:00 |
| Published | 2020-07-06T21:09:28 |
| Patch Date | 2020-07-03 |
| Last Updated | 2024-08-04T10:26:16 |
Community Chatter & Buzz