5.4
CVSSv3

CVE-2019-18990

Published: 30/09/2020 Updated: 21/07/2021
CVSS v2 Base Score: 4.8 | Impact Score: 4.9 | Exploitability Score: 6.5
CVSS v3 Base Score: 5.4 | Impact Score: 2.5 | Exploitability Score: 2.8
VMScore: 427
Vector: AV:A/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RTL8881AN 1.09 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an malicious user to discern information or potentially modify data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

realtek rtl8812ar_firmware 1.21ww

realtek rtl8196d_firmware 1.0.0

realtek rtl8192er_firmware 2.10

realtek rtl8881an_firmware 1.09