{
  "id": "CVE-2021-35394",
  "url": "https://spydr.io/cve/CVE-2021-35394",
  "published": "2021-08-16T12:15:07.267Z",
  "modified": "2026-06-17T03:57:29.187Z",
  "score": 9.8,
  "severity": "critical",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
  "score_source": "NVD",
  "epss": 0.99877,
  "epss_percentile": 0.99964,
  "exploited": true,
  "kev": {
    "added": "2021-12-10",
    "due": "2021-12-24",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Unknown",
    "name": "Realtek Jungle SDK Remote Code Execution Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-35394"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "realtek"
  ],
  "products": [
    "realtek rtl819x jungle software development kit"
  ],
  "cwes": [
    "CWE-78"
  ],
  "description": "Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 9.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain",
      "tags": [
        "Broken Link",
        "Exploit",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.realtek.com/en/cu-1-en/cu-1-taiwan-en",
      "tags": [
        "Broken Link",
        "Patch",
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://www.securityfocus.com/archive/1/534765",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-35394",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2021-35394",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
