Executive brief
The Realtek Jungle SDK contains multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability in the 'MP Daemon' diagnostic tool (UDPServer binary). Remote unauthenticated attackers can exploit these flaws to achieve remote code execution.
Affected products
- Realtek Jungle SDK v2.x through v3.4.14B
- Realtek RTL819x Jungle Software Development Kit v2.x through v3.4.14B
Timeline
- 2021-08-26: disclosed: Initial NVD analysis date
- 2021-12-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog