A stack buffer overflow in Realtek RTL8710 (and other Ameba-based devices) can lead to remote code execution via the "AES_UnWRAP" function, when an attacker in Wi-Fi range sends a crafted "Encrypted GTK" value as part of the WPA2 4-way-handshake.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.vdoo.com/blog/realtek-wifi-vulnerabilities-zero-day | third party advisory exploit |