CVE-2021-35394
Realtek Jungle SDK Remote Code Execution Vulnerability
Description
CVE-2021-35394 is a critical OS command injection and memory corruption vulnerability in the Realtek Jungle SDK that allows unauthenticated remote code execution. The vulnerability affects the 'MP Daemon' diagnostic tool, typically compiled as the 'UDPServer' binary, in Realtek Jungle SDK versions v2.x through v3.4.14B. An unauthenticated remote attacker can exploit multiple memory corruption flaws and an arbitrary command injection flaw to execute code on affected devices. This Realtek Jungle SDK vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog, and with an EPSS score of 93.80% (99.9th percentile), exploitation is near-certain for exposed devices.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| realtek | rtl819x jungle software development kit | >= 2.0, <= 3.4.14b |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain(Broken Link, Exploit, Third Party Advisory)
- https://www.realtek.com/en/cu-1-en/cu-1-taiwan-en(Broken Link, Patch, Vendor Advisory)
- https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf(Patch, Vendor Advisory)
- https://www.securityfocus.com/archive/1/534765(Broken Link, Third Party Advisory, VDB Entry)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-35394(US Government Resource)
Weakness Type
CWE-78: OS Command Injection
OS Command Injection occurs when software constructs operating system commands using externally-influenced input without properly neutralizing special elements that could modify the intended command. In the Realtek Jungle SDK, the UDPServer binary fails to sanitize input received over the network, allowing remote attackers to inject and execute arbitrary operating system commands on the underlying device with the privileges of the vulnerable service.
Learn more: CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Impact Analysis
CVE-2021-35394 carries a CVSS 3.1 score of 9.8 (CRITICAL), indicating maximum-severity risk. The vulnerability is remotely exploitable over the network with low attack complexity, requires no authentication, and needs no user interaction, making it trivially exploitable by automated attacks. Successful exploitation completely compromises confidentiality, integrity, and availability of the affected device, granting attackers full control. Since the Realtek Jungle SDK is embedded in a wide range of consumer and enterprise networking equipment including routers and IoT devices, the attack surface is enormous. The EPSS score of 93.80% confirms near-certain exploitation activity, and compromised devices are commonly recruited into botnets or used as pivot points for attacks against internal networks.
Exploit Maturity
CVE-2021-35394 is confirmed as actively exploited through its listing in the CISA Known Exploited Vulnerabilities catalog, with a remediation deadline of 2021-12-24. Public exploit information is available via the IoT Inspector advisory which documents the multiple vulnerability classes affecting the UDPServer binary. The EPSS score of 93.80% (99.9th percentile) indicates near-certain exploitation, and this vulnerability has been widely targeted by IoT botnets and automated scanning tools since its disclosure. The combination of unauthenticated remote access, widespread deployment in consumer networking hardware, and availability of exploit details makes this one of the most actively targeted IoT vulnerabilities.
Remediation
- Apply firmware updates from device manufacturers that incorporate the patched Realtek Jungle SDK, as mandated by CISA KEV. Contact your device vendor for updated firmware that addresses CVE-2021-35394.
- Verify all devices using the Realtek Jungle SDK v2.x through v3.4.14B have been identified in your asset inventory, including routers, access points, and IoT devices that may embed this SDK.
- If firmware updates are not yet available, isolate affected devices on a separate network segment, block inbound UDP traffic to the UDPServer diagnostic service from untrusted networks, and disable the MP Daemon service if not required for device operation.
- Monitor network traffic for indicators of exploitation, including unusual UDP connections to affected devices, unexpected outbound connections from IoT devices, and traffic patterns consistent with botnet command-and-control activity.
- Implement long-term network segmentation policies that isolate IoT and embedded devices from critical infrastructure, and establish a firmware update process to ensure timely patching of embedded device vulnerabilities.
Technical Details
CVE-2021-35394 affects the Realtek Jungle SDK's MP Daemon, a diagnostic tool compiled as the UDPServer binary included in SDK versions v2.x through v3.4.14B. The binary contains multiple vulnerability classes: memory corruption flaws that can be triggered remotely, and an arbitrary command injection vulnerability in the handling of network input. The OS command injection component (CWE-78) allows attackers to inject shell metacharacters into UDP packets processed by the UDPServer, which are then passed to system shell functions without proper sanitization. The CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects the severity of a network-accessible, unauthenticated vulnerability with complete impact across all security dimensions, making it an ideal target for automated exploitation by botnets scanning for vulnerable IoT infrastructure.
Frequently Asked Questions
Is CVE-2021-35394 being actively exploited?
Yes. CVE-2021-35394 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The EPSS score of 93.80% (99.9th percentile) indicates near-certain exploitation, and this vulnerability is widely targeted by IoT botnets.
What products are affected by CVE-2021-35394?
CVE-2021-35394 affects the Realtek RTL819x Jungle Software Development Kit versions 2.0 through 3.4.14B. This SDK is embedded in numerous networking devices from various manufacturers, including routers, access points, and IoT equipment that use Realtek chipsets.
How do I fix CVE-2021-35394?
Apply firmware updates from your device manufacturer that include the patched Realtek Jungle SDK. If no update is available, isolate affected devices from untrusted networks and block inbound UDP traffic to the UDPServer service. Contact your device vendor for specific patch availability.
How severe is CVE-2021-35394?
CVE-2021-35394 has a CVSS 3.1 score of 9.8 (CRITICAL). It allows unauthenticated remote code execution over the network with no user interaction required. The EPSS score of 93.80% places it in the 99.9th percentile for exploitation probability.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.