CVE-2021-35394
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Realtek Jungle SDK Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-78
מוצרים מושפעים
realtek: rtl819x jungle software development kit
קישורים
- https://www.realtek.com/en/cu-1-en/cu-1-taiwan-en Broken LinkPatchVendor Advisory
- https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2… PatchVendor Advisory
- https://www.realtek.com/en/cu-1-en/cu-1-taiwan-en Broken LinkPatchVendor Advisory
- https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2… PatchVendor Advisory
- https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-su… Broken LinkExploitThird Party Advisory
- https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-su… Broken LinkExploitThird Party Advisory
- https://www.securityfocus.com/archive/1/534765 Broken LinkThird Party AdvisoryVDB Entry
- https://www.securityfocus.com/archive/1/534765 Broken LinkThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource