Junglewise Threat Intelligence

CVE-2021-35394: Realtek Jungle SDK Remote Code Execution Vulnerability

CVE-2021-35394 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-12-10

Vendors: Realtek.

Executive brief

The Realtek Jungle SDK contains multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability in the 'MP Daemon' diagnostic tool (UDPServer binary). Remote unauthenticated attackers can exploit these flaws to achieve remote code execution.

Affected products

  • Realtek Jungle SDK v2.x through v3.4.14B
  • Realtek RTL819x Jungle Software Development Kit v2.x through v3.4.14B

Timeline

  • 2021-08-26: disclosed: Initial NVD analysis date
  • 2021-12-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog