Description
The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perform any access control checks on the write_mem (ioctl 0x89F5) and read_mem (ioctl 0x89F6) debug handlers, which are compiled into production builds via the unconditionally defined _IOCTL_DEBUG_CMD_ macro in 8192cd_cfg.h
Published: 2026-05-05
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 06 May 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Realtek
Realtek rtl8192cd
Vendors & Products Realtek
Realtek rtl8192cd

Tue, 05 May 2026 22:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Unchecked Debug IOCTLs in Realtek RTL8192CD Wi‑Fi Driver

Tue, 05 May 2026 20:15:00 +0000

Type Values Removed Values Added
Title Kernel‑Wide Read/Write Access Control Flaw in Realtek RTL8192CD Wi‑Fi Driver
Weaknesses CWE-250
CWE-292

Tue, 05 May 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-782
CWE-787
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 05 May 2026 16:00:00 +0000

Type Values Removed Values Added
Title Kernel‑Wide Read/Write Access Control Flaw in Realtek RTL8192CD Wi‑Fi Driver
Weaknesses CWE-250
CWE-292

Tue, 05 May 2026 14:00:00 +0000

Type Values Removed Values Added
Description The rtl8192cd Wi-Fi kernel driver in the Realtek rtl819x Jungle SDK (all known versions through v3.4.14B) does not perform any access control checks on the write_mem (ioctl 0x89F5) and read_mem (ioctl 0x89F6) debug handlers, which are compiled into production builds via the unconditionally defined _IOCTL_DEBUG_CMD_ macro in 8192cd_cfg.h
References

Subscriptions

Realtek Rtl8192cd
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-05T17:19:32.920Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36355

cve-icon Vulnrichment

Updated: 2026-05-05T17:17:55.959Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-05T14:16:08.737

Modified: 2026-05-07T15:53:49.717

Link: CVE-2026-36355

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-06T09:22:25Z

Weaknesses