S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2021-35395 Scanner

CVE-2021-35395 scanner - Arbitrary Command Injection vulnerability in RealTek Jungle SDK

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.2k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-35395
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access point. Two versions of this management interface exists: one based on Go-Ahead named webs and another based on Boa named boa. Both of them are affected by these vulnerabilities. Specifically, these binaries are vulnerable to the following issues: - stack buffer overflow in formRebootCheck due to unsafe copy of submit-url parameter - stack buffer overflow in formWsc due to unsafe copy of submit-url parameter - stack buffer overflow in formWlanMultipleAP due to unsafe copy of submit-url parameter - stack buffer overflow in formWlSiteSurvey due to unsafe copy of ifname parameter - stack buffer overflow in formStaticDHCP due to unsafe copy of hostname parameter - stack buffer overflow in formWsc due to unsafe copy of 'peerPin' parameter - arbitrary command execution in formSysCmd via the sysCmd parameter - arbitrary command injection in formWsc via the 'peerPin' parameter Exploitability of identified issues will differ based on what the end vendor/manufacturer did with the Realtek SDK webserver. Some vendors use it as-is, others add their own authentication implementation, some kept all the features from the server, some remove some of them, some inserted their own set of features. However, given that Realtek SDK implementation is full of insecure calls and that developers tends to re-use those examples in their custom code, any binary based on Realtek SDK webserver will probably contains its own set of issues on top of the Realtek ones (if kept). Successful exploitation of these issues allows remote attackers to gain arbitrary code execution on the device.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

RealTek's Jungle SDK is a widely used software development kit for creating firmware on various RealTek-based devices, including routers, IoT devices, and home networking equipment. It provides developers with tools and libraries to develop and deploy applications efficiently. Given its widespread use in network devices, vulnerabilities within this SDK can have significant implications, potentially affecting thousands of internet-connected devices across the globe.

The vulnerability stems from improper input validation in the formWsc page of the management interface. An attacker can inject and execute shell commands by sending specially crafted HTTP requests. This exploitation technique allows the attacker to bypass security mechanisms, execute code with the same privileges as the device's firmware, and modify the device's operations or compromise the device's security entirely.

The exploitation of this command injection vulnerability can lead to unauthorized access, data exfiltration, denial of service attacks, and the deployment of malware or ransomware. In a worst-case scenario, attackers could establish a foothold within a network, facilitating further attacks against connected devices and potentially accessing sensitive information.

Joining the S4E platform provides you access to cutting-edge vulnerability scanning technology, including the detection of critical vulnerabilities like CVE-2021-35395. Our service helps safeguard your digital assets by identifying and mitigating security risks before they can be exploited, thereby enhancing your overall cybersecurity posture and protecting against potential breaches.

 

References

Solution Advice
  1. Immediately apply any available security patches or updates from RealTek for the Jungle SDK.
  2. Ensure that devices using the RealTek Jungle SDK are not accessible from the internet where possible.
  3. Regularly monitor and audit network traffic for suspicious activities indicative of exploitation attempts.
  4. Consider implementing additional network segmentation to limit the impact of potential compromises.
  5. Educate staff on the importance of applying security updates in a timely manner to prevent exploitations.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.