CVE-2025-8299 is a heap-based buffer overflow vulnerability in the Realtek rtl81xx SDK Wi-Fi driver, specifically within the MgntActSet_TEREDO_SET_RS_PACKET function, affecting products like realtek rtl8811au and wi_fi_usb_driver. This flaw allows a local attacker with low-privileged code execution to escalate privileges to SYSTEM due to insufficient validation of user-supplied data length. With a CVSS score of 8.8 (HIGH), it presents a significant risk for privilege escalation. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1030.52.0325.2025CPE matchmatch criteria | cpe:2.3:a:realtek:wi-fi_usb_driver:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.