PT-2022-4237 · Realtek · Realtek Ecos Rsdk+1

Octavio Galland

+1

·

Published

2022-08-01

·

Updated

2025-12-03

·

CVE-2022-27255

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Realtek eCos RSDK version 1.5.7p1 Realtek MSDK version 4.9.4p1
Description The SIP ALG function in Realtek eCos RSDK and MSDK has a stack-based buffer overflow that allows an attacker to remotely execute code without authentication via a crafted SIP packet containing malicious SDP data. This issue can be exploited by sending a specially crafted UDP packet, and it does not require user interaction or access to the admin interface. The vulnerability is notable for allowing attacks on devices with disabled web interface access from external networks. Potentially, millions of devices, from routers to signal amplifiers, are affected.
Recommendations For Realtek eCos RSDK version 1.5.7p1, consider disabling the SIP ALG function as a temporary workaround until a patch is available. For Realtek MSDK version 4.9.4p1, restrict access to the SIP ALG function to minimize the risk of exploitation until a fix is provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Stack Overflow

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-05085
CVE-2022-27255

Affected Products

Realtek Sdk
Realtek Ecos Rsdk