FAIL › dossier
Realtek
VENDOR· dossier confidence 50%
Realtek is a major semiconductor vendor whose SDKs and router firmware have repeatedly shipped with high-severity RCE and memory corruption flaws, requiring defense-in-depth controls for any DIB systems relying on its components.
PROFILE
Categorysemiconductor & embedded software vendorWhat they doRealtek Semiconductor Corporation designs and manufactures semiconductors, including Wi-Fi, Bluetooth, and audio chips, and provides SDKs for embedded devices.
SECURITY POSTURE
Realtek has a history of high-severity remote code execution and memory corruption vulnerabilities in its SDKs and router software, indicating inconsistent input validation and memory safety practices across its product lines.
Notable failures
- CVE-2014-8361: SDK RCE via improper input validation
- CVE-2021-35394: Jungle SDK memory corruption RCE
- CVE-2021-35395: AP-Router SDK HTTP server buffer overflow DoS
Patterns: repeated unpatched edge-device RCEs; memory corruption in SDKs; unsafe input handling in router firmware
FAILURE HISTORY · 3
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-12-10 | CVE-2021-35394 | high | Realtek Jungle SDK shipped with multiple memory corruption flaws enabling remote code execution. |
| 2023-09-18 | CVE-2014-8361 | high | Realtek SDK allows remote code execution via improper input validation. |
| 2021-11-03 | CVE-2021-35395 | high | Realtek AP-Router SDK HTTP web server boa suffered a buffer overflow vulnerability allowing denial-of-service via unsafe parameter copying. |
SENTIMENT · TRUSTED SOURCES
synthesisneutral+0.00
No coverage found for CVE-2021-35395 in provided sources.
Neutral; only factual CVE description provided.
"Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some overly long parameters submitted in the form that lead to denial-of-service (DoS)."
Irrelevant; discusses Siemens S7 PLCs, not Realtek.
"Defending Against an Active Threat to Siemens S7 Series PLCs | CISA"
Irrelevant; generic CVE database site.
"CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws."
Irrelevant; discusses Cisco Secure Workload Software, not Realtek.
"Cisco Secure Workload Software Security Hardening Release: August 2026"
Irrelevant; discusses T-Mobile and Chinese hackers, not Realtek.
"T-Mobile 'chopped a cable' to expel Chinese hackers from its network"
Irrelevant; site error page.
"Client Challenge A required part of this site couldn't load."
Irrelevant; generic CVE search site.
"CVEs and Security Vulnerabilities - OpenCVE"
Open questions: Current patch cadence for Realtek SDKs · Whether DIBs using Realtek components have implemented compensating controls
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-11 03:55:03.191020+00:00