Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Realtek

First CVE: Apr 25, 2008Active for: 18 yearsTotal CVEs: 73
66.9
VTI Score
TOP TARGET

Realtek's vulnerability footprint spans a well-represented portfolio of embedded networking and wireless components, including wireless drivers, Wi-Fi adapters, and firmware platforms such as the RTL819x Jungle SDK and RTL8195a series, that are widely integrated into consumer routers, IoT devices, and network appliances. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated tendency toward critical severity, and a moderate share acquire public exploit code. The exposure recurs through memory-safety weakness classes dominated by buffer overflows—including stack-based, heap-based, and out-of-bounds writes—reflecting the low-level nature of firmware and driver codebases and their limited opportunity for modern defensive tooling. Defenders should prioritize inventory and patching of internet-exposed network devices shipping Realtek components, as these embedded platforms often remain in service well beyond vendor support timelines; current exploitation and severity counts are shown alongside this summary.

FAUCET AI Generated
73
Total CVEs
More Total CVEs than 99% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 71% of tracked vendors
4.1%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Realtek over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 25, 2008
18 years ago
Most Recent CVE
Sep 2, 2025
325 days ago

Products(69 total)

Top CVEs

Signals from CVEs in this vendor scope (73 CVEs).

73 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-35394CRITICAL
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memo
Aug 16, 20219.898YESYES
CVE-2014-8361CRITICAL
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
May 1, 20159.898YESYES
CVE-2021-35395CRITICAL
Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access point. Two versions of this mana
Aug 16, 20219.897YESYES
CVE-2021-35393CRITICAL
Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usually named wscd or mini_upnpd a
Aug 16, 20219.869NONO
CVE-2021-35392HIGH
Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usually named wscd or mini_upnpd a
Aug 16, 20217.569NONO
CVE-2008-5664HIGH
Stack-based buffer overflow in Realtek Media Player (aka Realtek Sound Manager, RtlRack, or rtlrack.exe) 1.15.0.0 allows remote attackers to execute arbitrary code via a crafted pl
Dec 19, 20089.361NOYES
CVE-2022-27255CRITICAL
In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a stack-based buffer overflow. This allows an attacker to remotely execute code witho
Aug 1, 20229.850NONO
CVE-2019-19822HIGH
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (u
Jan 27, 20207.537NOYES
CVE-2019-19823HIGH
A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affe
Jan 27, 20207.535NOYES
CVE-2021-43573CRITICAL
A buffer overflow was discovered on Realtek RTL8195AM devices before 2.0.10. It exists in the client code when processing a malformed IE length of HT capability information in the
Nov 11, 20219.830NONO
View all 73 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products73 CVEs
19%
67%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local16 (21.9%)
Network42 (57.5%)
Unknown3 (4.1%)
Physical1 (1.4%)
Adjacent Network11 (15.1%)
Attack Complexity
Low66 (90.4%)
High4 (5.5%)
Unknown3 (4.1%)
User Interaction
None68 (93.2%)
Unknown3 (4.1%)
Required2 (2.7%)
Privileges Required
Low21 (28.8%)
High19 (26.0%)
None30 (41.1%)
Unknown3 (4.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (73 CVEs).

CISA KEV
3 CVEs
4.1% of CVEs· 99th percentile
Metasploit
2 CVEs
2.7% of CVEs· 98th percentile
Nuclei
4 CVEs
5.5% of CVEs· 96th percentile
ExploitDB
2 CVEs
2.7% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Realtek.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Realtek — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Realtek's Products

View all 6 CNAs →

Top CWEs