CVE-2020-25854 is a stack buffer overflow vulnerability in the Realtek RTL8195A Wi-Fi Module (versions prior to April 2020) caused by improper size validation in the DecWPA2KeyData() function. This flaw allows an attacker to impersonate an Access Point and, with knowledge of the network's PSK, inject a crafted packet during the WPA2 handshake. Rated 8.1 HIGH on CVSS, it carries a high risk of remote code execution or denial of service due to its network attack vector and high impact. While no public exploits or active exploitation have been observed, and community discussion is minimal, the vulnerability's severity warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.08CPE matchmatch criteria | cpe:2.3:o:realtek:rtl8195a_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.