Realtek's vulnerability footprint spans a well-represented portfolio of embedded networking and wireless components, including wireless drivers, Wi-Fi adapters, and firmware platforms such as the RTL819x Jungle SDK and RTL8195a series, that are widely integrated into consumer routers, IoT devices, and network appliances. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated tendency toward critical severity, and a moderate share acquire public exploit code. The exposure recurs through memory-safety weakness classes dominated by buffer overflows—including stack-based, heap-based, and out-of-bounds writes—reflecting the low-level nature of firmware and driver codebases and their limited opportunity for modern defensive tooling. Defenders should prioritize inventory and patching of internet-exposed network devices shipping Realtek components, as these embedded platforms often remain in service well beyond vendor support timelines; current exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Realtek over time
Signals from CVEs in this vendor scope (73 CVEs).
73 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-35394CRITICAL Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memo | Aug 16, 2021 | 9.8 | 98 | YES | YES |
CVE-2014-8361CRITICAL The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023. | May 1, 2015 | 9.8 | 98 | YES | YES |
CVE-2021-35395CRITICAL Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access point. Two versions of this mana | Aug 16, 2021 | 9.8 | 97 | YES | YES |
CVE-2021-35393CRITICAL Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usually named wscd or mini_upnpd a | Aug 16, 2021 | 9.8 | 69 | NO | NO |
CVE-2021-35392HIGH Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usually named wscd or mini_upnpd a | Aug 16, 2021 | 7.5 | 69 | NO | NO |
CVE-2008-5664HIGH Stack-based buffer overflow in Realtek Media Player (aka Realtek Sound Manager, RtlRack, or rtlrack.exe) 1.15.0.0 allows remote attackers to execute arbitrary code via a crafted pl | Dec 19, 2008 | 9.3 | 61 | NO | YES |
CVE-2022-27255CRITICAL In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows an attacker to remotely execute code witho | Aug 1, 2022 | 9.8 | 50 | NO | NO |
CVE-2019-19822HIGH A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (u | Jan 27, 2020 | 7.5 | 37 | NO | YES |
CVE-2019-19823HIGH A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affe | Jan 27, 2020 | 7.5 | 35 | NO | YES |
CVE-2021-43573CRITICAL A buffer overflow was discovered on Realtek RTL8195AM devices before 2.0.10. It exists in the client code when processing a malformed IE length of HT capability information in the | Nov 11, 2021 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (73 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Realtek.
Media articles that mention a CVE ID that affects a product developed by Realtek — matched by CVE ID, not by vendor name.