Vulnerability Description
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Realtek | Rtl819X Jungle Software Development Kit | >= 2.0, <= 3.4.14b |
Related Weaknesses (CWE)
References
- https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-suppBroken LinkExploitThird Party Advisory
- https://www.realtek.com/en/cu-1-en/cu-1-taiwan-enBroken LinkPatchVendor Advisory
- https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-202PatchVendor Advisory
- https://www.securityfocus.com/archive/1/534765Broken LinkThird Party AdvisoryVDB Entry
- https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-suppBroken LinkExploitThird Party Advisory
- https://www.realtek.com/en/cu-1-en/cu-1-taiwan-enBroken LinkPatchVendor Advisory
- https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-202PatchVendor Advisory
- https://www.securityfocus.com/archive/1/534765Broken LinkThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-US Government Resource
FAQ
What is CVE-2021-35394?
CVE-2021-35394 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulner...
How severe is CVE-2021-35394?
CVE-2021-35394 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-35394?
Check the references section above for vendor advisories and patch information. Affected products include: Realtek Rtl819X Jungle Software Development Kit.