Executive brief
The Realtek Jungle SDK HTTP web server (both 'webs' and 'boa' implementations) contains multiple stack buffer overflows and command injection vulnerabilities. These flaws arise from unsafe handling of parameters such as submit-url, ifname, hostname, and peerPin, allowing remote attackers to achieve arbitrary code execution or denial-of-service.
Affected products
- Realtek Jungle SDK v2.x up to v3.4.14B
- Realtek RTL819x Jungle SDK v2.x up to v3.4.14B
Timeline
- 2021-11-03: disclosed
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild at time of publication.