CVE-2022-27255 is a critical stack-based buffer overflow vulnerability in the SIP ALG function of Realtek eCos RSDK and MSDK, affecting various Realtek SDK-based devices. This flaw allows unauthenticated, remote code execution through specially crafted SIP packets containing malicious SDP data. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, there is significant public awareness, with media coverage and community discussion indicating active interest and the potential for future exploitation, though no public exploit code or Metasploit modules are currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.7p1CPE matchmatch criteria | cpe:2.3:o:realtek:ecos_rsdk_firmware:1.5.7p1:*:*:*:*:*:*:* | ||
4.9.4p1CPE matchmatch criteria | cpe:2.3:o:realtek:ecos_msdk_firmware:4.9.4p1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.