{"id":"CVE-2025-8299","title":"Realtek rtl81xx SDK Wi-Fi Driver MgntActSet_TEREDO_SET_RS_PACKET Heap-based Buffer Overflow Local Privilege Escalation Vulnerability","summary":"Realtek rtl81xx SDK Wi-Fi Driver MgntActSet_TEREDO_SET_RS_PACKET Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Realtek r…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-122"],"vendor":"realtek","product":"wi-fi_usb_driver","affected":["wi-fi_usb_driver < 1030.52.0325.2025"],"patched":["wi-fi_usb_driver 1030.52.0325.2025"],"published":"2025-09-02","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:10:00.237","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-8299","references":[{"url":"https://www.zerodayinitiative.com/advisories/ZDI-25-882/","label":"zdi-disclosures@trendmicro.com"}],"tags":["nvd"],"epss":0.00152,"epssPercentile":0.03743,"zeroDay":true,"ingestedAt":"2026-09-30T23:29:32.354Z","slug":"CVE-2025-8299","body":"## Overview\n\nRealtek rtl81xx SDK Wi-Fi Driver MgntActSet_TEREDO_SET_RS_PACKET Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Realtek rtl81xx SDK Wi-Fi driver. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the MgntActSet_TEREDO_SET_RS_PACKET function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-25857.\n\n## Affected\n\n- `wi-fi_usb_driver < 1030.52.0325.2025`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `wi-fi_usb_driver 1030.52.0325.2025`","depth":"abyssal","depthScore":73,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":25,"ransomware":0},"changes":[]}