Junglewise Threat Intelligence

CVE-2026-36355: Realtek rtl819x Jungle SDK Kernel Memory Read/Write in Wi-Fi Driver

CVE-2026-36355 · Severity: high · CVSS 7.7 · Published 2026-05-05

Vendors: Realtek.

Executive brief

A vulnerability exists in the Wi-Fi software driver used by many home and enterprise routers and networking devices. This flaw allows a person with basic access to the device's command line to bypass security protections and gain full administrative (root) control. Once in control, an attacker could monitor network traffic, modify device settings, or use the device as a foothold to attack other systems on the network.

Technical details

The rtl8192cd Wi-Fi kernel driver fails to implement access control checks on the write_mem (ioctl 0x89F5) and read_mem (ioctl 0x89F6) debug handlers. These handlers are enabled in production builds because the _IOCTL_DEBUG_CMD_ macro is unconditionally defined in the driver configuration. A local attacker can use these IOCTLs to perform arbitrary kernel memory reads and writes without requiring root privileges or specialized capabilities. This primitive can be used to overwrite process credentials (e.g., task_struct->cred) to achieve local privilege escalation (LPE) to root. The vulnerability affects the Realtek rtl819x Jungle SDK through version v3.4.14B and is present in various driver variants including rtl8192cd, rtl8192es, and others.

Affected products

  • Realtek rtl819x Jungle SDK All versions through v3.4.14B

Timeline

  • 2026-02-23: other: Vulnerability confirmed in test environment
  • 2026-05-03: disclosed: Initial disclosure by researcher
  • 2026-05-05: advisory: NVD publication date

References