PT-2022-4237 · Realtek · Realtek Ecos Rsdk+1
Octavio Galland
+1
·
Published
2022-08-01
·
Updated
2025-12-03
·
CVE-2022-27255
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Realtek eCos RSDK version 1.5.7p1
Realtek MSDK version 4.9.4p1
Description
The SIP ALG function in Realtek eCos RSDK and MSDK has a stack-based buffer overflow that allows an attacker to remotely execute code without authentication via a crafted SIP packet containing malicious SDP data. This issue can be exploited by sending a specially crafted UDP packet, and it does not require user interaction or access to the admin interface. The vulnerability is notable for allowing attacks on devices with disabled web interface access from external networks. Potentially, millions of devices, from routers to signal amplifiers, are affected.
Recommendations
For Realtek eCos RSDK version 1.5.7p1, consider disabling the SIP ALG function as a temporary workaround until a patch is available.
For Realtek MSDK version 4.9.4p1, restrict access to the SIP ALG function to minimize the risk of exploitation until a fix is provided.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Stack Overflow
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Realtek Sdk
Realtek Ecos Rsdk