CVE-2021-35394
realtek rtl819x jungle software development kit
Published 16 Aug 2021 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 10 Dec 2021, with a remediation deadline of 24 Dec 2021 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.
References
- www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain · Broken Link, Exploit, Third Party Advisory
- www.realtek.com/en/cu-1-en/cu-1-taiwan-en · Broken Link, Patch, Vendor Advisory
- www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf · Patch, Vendor Advisory
- www.securityfocus.com/archive/1/534765 · Broken Link, Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-35394 · US Government Resource