CVE-2019-18990

A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RTL8881AN 1.09 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an attacker to discern information or potentially modify data.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
mitreCNA
6.1 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.0/AC:L/AV:A/A:N/C:L/I:L/PR:N/S:C/UI:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 8%
VendorProductVersion
realtekrtl8812ar_firmware
1.21ww:ww
realtekrtl8196d_firmware
1.0.0
realtekrtl8192er_firmware
2.10
realtekrtl8881an_firmware
1.09
𝑥
= Vulnerable software versions