← Vulnerability feed

Vulnerability record · CVE-2021-35392 · published 16 August 2021

CVE-2021-35392: Realtek Jungle SDK wscd SSDP heap buffer overflow

RRealtek · Rtl819x Jungle Software Development Kit

The Realtek Jungle SDK (v2.x up to v3.4.14B) ships a WiFi Simple Config server (wscd or mini_upnpd) that implements UPnP and SSDP. It writes past a heap buffer when crafting SSDP NOTIFY messages from the ST header of received M-SEARCH messages. Because this SDK is embedded in many routers and IoT devices, the flaw affects a broad downstream supply chain rather than a single product.

7.5 CVSS 3.1 High EPSS 83% · top 0.3% CWE-787 · Out-of-bounds write
7.5CVSS 3.1 base score, v2 7.8
83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usually named wscd or mini_upnpd and is the successor to miniigd. The server is vulnerable to a heap buffer overflow that is present due to unsafe crafting of SSDP NOTIFY messages from received M-SEARCH messages ST header.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRemote unauthenticated heap overflow with public exploit references and very high EPSS, though impact is limited to availability per the CVSS vector and no KEV listing exists.

What it is

The Realtek Jungle SDK (v2.x up to v3.4.14B) ships a WiFi Simple Config server (wscd or mini_upnpd) that implements UPnP and SSDP. It writes past a heap buffer when crafting SSDP NOTIFY messages from the ST header of received M-SEARCH messages. Because this SDK is embedded in many routers and IoT devices, the flaw affects a broad downstream supply chain rather than a single product.

Impact

A remote unauthenticated attacker can trigger an out-of-bounds heap write, causing a denial of service (crash or restart) of the affected service or device. The CVSS vector rates only availability impact, so code execution is not established by the record.

Attack surface

Reachable over the network via SSDP/UPnP traffic on the local or exposed network segment; the CVSS vector shows no privileges and no user interaction required. Any host that can send an M-SEARCH request to the wscd/mini_upnpd listener can reach the vulnerable parsing path.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.8315, 99.66th percentile), and the advisory references are tagged Exploit, indicating public exploit material exists. No ransomware usage is documented.

What to do

  • Apply the Realtek vendor patch referenced in the Realtek APRouter SDK advisory (CVE-2021-35392_35395) or the vendor update page; if the device vendor has not shipped firmware, replace or isolate the device.
  • Disable UPnP/SSDP and the WiFi Simple Config (WSC) service on affected devices where the feature is not required.
  • Block inbound SSDP/UPnP (UDP 1900 and related ports) at network boundaries and segment IoT/embedded devices away from critical assets.
  • Monitor vendor firmware advisories for downstream products built on the Jungle SDK and patch them as updates become available.

Detection

  • Monitor for abnormal or malformed SSDP M-SEARCH requests with oversized or unusual ST headers targeting UDP 1900.
  • Alert on unexpected crashes or restarts of wscd/mini_upnpd processes on routers and embedded devices.
  • Baseline normal SSDP discovery traffic per segment and flag spikes or scans from untrusted hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-35392 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-35394Realtek Jungle SDK MP Daemon command injection and memory corruptionThe Realtek Jungle SDK (v2.x through v3.4.14B) ships a diagnostic tool called MP Daemon, usually compiled as the UDPServer binary, which contains mul…KEVEPSS 100%analysed9.8CVE-2021-35395Realtek Jungle SDK web server buffer overflow and command injectionThe Realtek Jungle SDK (v2.x through v3.4.14B) ships an HTTP management interface, in both Go-Ahead 'webs' and Boa 'boa' variants, that mishandles se…KEVEPSS 98%analysed9.8CVE-2021-35393Realtek Jungle SDK wscd UPnP SUBSCRIBE Callback stack buffer overflowThe Realtek Jungle SDK (v2.x up to v3.4.14B) ships a WiFi Simple Config server (wscd/mini_upnpd) that implements UPnP and SSDP. It parses the UPnP SU…EPSS 70%analysed8.8CVE-2023-47677Realtek rtl819x jungle software development kit cross-site request forgery vulnerabilityA cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially …EPSS 0.37%7.2CVE-2023-50382Realtek rtl819x jungle software development kit os command injection vulnerabilityThree os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series o…EPSS 1.9%7.2CVE-2023-50383Realtek rtl819x jungle software development kit os command injection vulnerabilityThree os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series o…EPSS 1.9%7.2CVE-2024-21778Realtek rtl819x jungle software development kit heap-based buffer overflow vulnerabilityA heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realtek rtl819x Jungle SDK v3.4.11.…EPSS 0.94%7.2CVE-2023-50243Realtek rtl819x jungle software development kit stack-based buffer overflow vulnerabilityTwo stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted s…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2021-35392), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.