Skip to content
COOEY

FAIL › dossier

Realtek

VENDOR

· dossier confidence 50%

Realtek is a major semiconductor vendor whose SDKs and router firmware have repeatedly shipped with high-severity RCE and memory corruption flaws, requiring defense-in-depth controls for any DIB systems relying on its components.

PROFILE
Categorysemiconductor & embedded software vendorWhat they doRealtek Semiconductor Corporation designs and manufactures semiconductors, including Wi-Fi, Bluetooth, and audio chips, and provides SDKs for embedded devices.
SECURITY POSTURE

Realtek has a history of high-severity remote code execution and memory corruption vulnerabilities in its SDKs and router software, indicating inconsistent input validation and memory safety practices across its product lines.

Notable failures
  • CVE-2014-8361: SDK RCE via improper input validation
  • CVE-2021-35394: Jungle SDK memory corruption RCE
  • CVE-2021-35395: AP-Router SDK HTTP server buffer overflow DoS
Patterns: repeated unpatched edge-device RCEs; memory corruption in SDKs; unsafe input handling in router firmware
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2021-12-10 CVE-2021-35394 high Realtek Jungle SDK shipped with multiple memory corruption flaws enabling remote code execution.
2023-09-18 CVE-2014-8361 high Realtek SDK allows remote code execution via improper input validation.
2021-11-03 CVE-2021-35395 high Realtek AP-Router SDK HTTP web server boa suffered a buffer overflow vulnerability allowing denial-of-service via unsafe parameter copying.
SENTIMENT · TRUSTED SOURCES
synthesisneutral+0.00
No coverage found for CVE-2021-35395 in provided sources.
cooey ↗neutral+0.00
Neutral; only factual CVE description provided.
"Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some overly long parameters submitted in the form that lead to denial-of-service (DoS)."
CISA ↗neutral+0.00
Irrelevant; discusses Siemens S7 PLCs, not Realtek.
"Defending Against an Active Threat to Siemens S7 Series PLCs | CISA"
Irrelevant; generic CVE database site.
"CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws."
Irrelevant; discusses Cisco Secure Workload Software, not Realtek.
"Cisco Secure Workload Software Security Hardening Release: August 2026"
techcrunch.com ↗neutral+0.00
Irrelevant; discusses T-Mobile and Chinese hackers, not Realtek.
"T-Mobile 'chopped a cable' to expel Chinese hackers from its network"
www.arista.com ↗neutral+0.00
Irrelevant; site error page.
"Client Challenge A required part of this site couldn't load."
app.opencve.io ↗neutral+0.00
Irrelevant; generic CVE search site.
"CVEs and Security Vulnerabilities - OpenCVE"
Open questions: Current patch cadence for Realtek SDKs · Whether DIBs using Realtek components have implemented compensating controls
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-11 03:55:03.191020+00:00