Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-28660

28
FAUCET Score

CVE-2021-28660 is a high-severity vulnerability in the Linux kernel's rtl8188eu Wi-Fi driver, specifically affecting the rtw_wx_set_scan function. This flaw allows an attacker to write beyond the allocated buffer for the SSID array, potentially leading to arbitrary code execution or denial of service. With a CVSS score of 8.8, it can be exploited remotely with low complexity and no user interaction, resulting in high impact to confidentiality, integrity, and availability. Currently, there is no public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.12, < 4.4.262CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.5, < 4.9.262CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.10, < 4.14.226CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.15, < 4.19.181CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 4.20, < 5.4.106CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.32%
Probability of exploitation in next 30 days
EPSS Percentile
67.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0132 is in the 82nd percentile among its peer group of 1,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

microsoftpatch availablevia msrc
Product: 16920-16823Fixed in: 5.10.78.1-1
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.10.78.1-1 on CBL Mariner 2.0Fixed in: 5.10.78.1-1

Vendor Advisories (2)

redhatCVE-2021-28660Moderate

kernel: buffer overflow in rtw_wx_set_scan function in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c

Mar 10, 2021
microsoft2021-Mar/CVE-2021-28660Important

rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases CVE IDs are not normally used for drivers/staging/* (unfinished work); however system integrators may have situations in which a drivers/staging issue is relevant to their own customer base.

Mar 9, 2021

References

git.kernel.org / pub/scm/linux/kernel/git/torvalds/linux.git/commit
Mailing ListPatchVendor Advisory
lists.debian.org / debian-lts-announce/2021/03/msg00035.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2021/06/msg00020.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/TJPVQZPY3DHPV5I3IVNMSMO6D3PKZISX
security.netapp.com / advisory/ntap-20210507-0008
Third Party Advisory
openwall.com / lists/oss-security/2022/11/18/1
Third Party Advisory
openwall.com / lists/oss-security/2022/11/21/2
Third Party Advisory