Vulnerability record · CVE-2021-35392 · published 16 August 2021
CVE-2021-35392: Realtek Jungle SDK wscd SSDP heap buffer overflow
RRealtek · Rtl819x Jungle Software Development Kit
The Realtek Jungle SDK (v2.x up to v3.4.14B) ships a WiFi Simple Config server (wscd or mini_upnpd) that implements UPnP and SSDP. It writes past a heap buffer when crafting SSDP NOTIFY messages from the ST header of received M-SEARCH messages. Because this SDK is embedded in many routers and IoT devices, the flaw affects a broad downstream supply chain rather than a single product.
Description
Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usually named wscd or mini_upnpd and is the successor to miniigd. The server is vulnerable to a heap buffer overflow that is present due to unsafe crafting of SSDP NOTIFY messages from received M-SEARCH messages ST header.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityRemote unauthenticated heap overflow with public exploit references and very high EPSS, though impact is limited to availability per the CVSS vector and no KEV listing exists.
What it is
The Realtek Jungle SDK (v2.x up to v3.4.14B) ships a WiFi Simple Config server (wscd or mini_upnpd) that implements UPnP and SSDP. It writes past a heap buffer when crafting SSDP NOTIFY messages from the ST header of received M-SEARCH messages. Because this SDK is embedded in many routers and IoT devices, the flaw affects a broad downstream supply chain rather than a single product.
Impact
A remote unauthenticated attacker can trigger an out-of-bounds heap write, causing a denial of service (crash or restart) of the affected service or device. The CVSS vector rates only availability impact, so code execution is not established by the record.
Attack surface
Reachable over the network via SSDP/UPnP traffic on the local or exposed network segment; the CVSS vector shows no privileges and no user interaction required. Any host that can send an M-SEARCH request to the wscd/mini_upnpd listener can reach the vulnerable parsing path.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.8315, 99.66th percentile), and the advisory references are tagged Exploit, indicating public exploit material exists. No ransomware usage is documented.
What to do
- Apply the Realtek vendor patch referenced in the Realtek APRouter SDK advisory (CVE-2021-35392_35395) or the vendor update page; if the device vendor has not shipped firmware, replace or isolate the device.
- Disable UPnP/SSDP and the WiFi Simple Config (WSC) service on affected devices where the feature is not required.
- Block inbound SSDP/UPnP (UDP 1900 and related ports) at network boundaries and segment IoT/embedded devices away from critical assets.
- Monitor vendor firmware advisories for downstream products built on the Jungle SDK and patch them as updates become available.
Detection
- Monitor for abnormal or malformed SSDP M-SEARCH requests with oversized or unusual ST headers targeting UDP 1900.
- Alert on unexpected crashes or restarts of wscd/mini_upnpd processes on routers and embedded devices.
- Baseline normal SSDP discovery traffic per segment and flag spikes or scans from untrusted hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain | Broken LinkExploitThird Party Advisory |
| https://www.realtek.com/en/cu-1-en/cu-1-taiwan-en | Broken LinkPatchVendor Advisory |
| https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf | PatchVendor Advisory |
| https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain | Broken LinkExploitThird Party Advisory |
| https://www.realtek.com/en/cu-1-en/cu-1-taiwan-en | Broken LinkPatchVendor Advisory |
| https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf | PatchVendor Advisory |
Track CVE-2021-35392 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-35392), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.