References https://www.twcert.org.tw/tw/cp-132-6459-09c82-1.html https://nvd.nist.gov/vuln/detail/CVE-2022-26529 https://www.realtek.com/images/safe-report/Security_Advisory-oob-by-inconsistent-msg-type.pdf https://nvd.nist.gov/vuln/detail/CVE-2022-26527 https://nvd.nist.gov/vuln/detail/CVE-2022-26528 https://cve.yack.one/products/realtek:bluetooth-mesh-software-development-kit
Related VulnerabilitiesPoCCVE-2019-11043: PHP-FPM Path Info Buffer Underflow - Remote Code ExecutionPoCCVE-2019-19822: TOTOLINK/Realtek Routers - Information DisclosurePoCCVE-2019-19823: TOTOLINK/Realtek Routers - Information DisclosurePoCCVE-2019-19825: TOTOLINK/Realtek Routers - CAPTCHA BypassPoCCVE-2022-42475: Fortinet SSL-VPN - Heap-Based Buffer OverflowPoCCVE-2025-22457: Ivanti Connect Secure - Stack-based Buffer OverflowPoCCVE-2019-19824: TOTOLINK Realtek SD Routers - Remote Command InjectionPoCCVE-2021-20038: SonicWall SMA100 Stack - Buffer Overflow/Remote Code ExecutionPoCCVE-2021-20167: Netgear RAX43 1.0.3.96 - Command Injection/Authentication Bypass Buffer OverrunPoCCVE-2021-35395: RealTek Jungle SDK - Arbitrary Command InjectionPoCCVE-2022-0968: Microweber <1.2.12 - Integer OverflowPoCCVE-2021-35394: RealTek AP Router SDK - Arbitrary Command InjectionPoCCVE-2019-5544: VMware ESXi SLP - Heap Overflow DoS