CVE-2025-44526

Realtek RTL8762EKF-EVB RTL8762E SDK V1.4.0 was discovered to utilize insufficient permission checks on critical fields within Bluetooth Low Energy (BLE) data packets. This issue allows attackers to cause a Denial of Service (DoS) via a crafted LL_Length_Req packet.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:realtek:rtl8762e_software_development_kit:1.4.0:*:*:*:*:*:*:*
cpe:2.3:h:realtek:rtl8762ekf-evb:-:*:*:*:*:*:*:*

History

18 Jul 2025, 17:48

Type Values Removed Values Added
References () http://realtek.com - () http://realtek.com - Broken Link
References () http://rtl8762ekf-evb.com - () http://rtl8762ekf-evb.com - Broken Link
References () https://github.com/yangting111/BLE_TEST/blob/main/result/PoC/Realtek/Improper_Validation_of_BLE_PDU_Length.md - () https://github.com/yangting111/BLE_TEST/blob/main/result/PoC/Realtek/Improper_Validation_of_BLE_PDU_Length.md - Exploit, Third Party Advisory
CPE cpe:2.3:h:realtek:rtl8762ekf-evb:-:*:*:*:*:*:*:*
cpe:2.3:a:realtek:rtl8762e_software_development_kit:1.4.0:*:*:*:*:*:*:*
First Time Realtek rtl8762e Software Development Kit
Realtek rtl8762ekf-evb
Realtek

10 Jul 2025, 13:17

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-09 16:15

Updated : 2025-07-18 17:48


NVD link : CVE-2025-44526

Mitre link : CVE-2025-44526

CVE.ORG link : CVE-2025-44526


JSON object : View

Products Affected

realtek

  • rtl8762ekf-evb
  • rtl8762e_software_development_kit
CWE
CWE-20

Improper Input Validation

CWE-284

Improper Access Control