Vulnerability record · CVE-2021-35393 · published 16 August 2021
CVE-2021-35393: Realtek Jungle SDK wscd UPnP SUBSCRIBE Callback stack buffer overflow
RRealtek · Rtl819x Jungle Software Development Kit
The Realtek Jungle SDK (v2.x up to v3.4.14B) ships a WiFi Simple Config server (wscd/mini_upnpd) that implements UPnP and SSDP. It parses the UPnP SUBSCRIBE/UNSUBSCRIBE Callback header unsafely, causing a stack buffer overflow. Because the service is network-facing and unauthenticated, this is a serious pre-auth remote code execution flaw in a widely embedded SDK.
Description
Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usually named wscd or mini_upnpd and is the successor to miniigd. The server is vulnerable to a stack buffer overflow vulnerability that is present due to unsafe parsing of the UPnP SUBSCRIBE/UNSUBSCRIBE Callback header. Successful exploitation of this vulnerability allows remote unauthenticated attackers to gain arbitrary code execution on the affected device.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network, unauthenticated, no-interaction remote code execution, high EPSS, and public exploit references make this an urgent pre-auth RCE in widely deployed embedded firmware.
What it is
The Realtek Jungle SDK (v2.x up to v3.4.14B) ships a WiFi Simple Config server (wscd/mini_upnpd) that implements UPnP and SSDP. It parses the UPnP SUBSCRIBE/UNSUBSCRIBE Callback header unsafely, causing a stack buffer overflow. Because the service is network-facing and unauthenticated, this is a serious pre-auth remote code execution flaw in a widely embedded SDK.
Impact
A remote unauthenticated attacker can achieve arbitrary code execution on the affected device, gaining full control of the embedded system. This can lead to persistent compromise, botnet enrollment, or use as a pivot into the local network.
Attack surface
Reachable over the network via the UPnP/SSDP service (wscd or mini_upnpd) listening on the device; the CVSS vector shows AV:N/AC:L/PR:N/UI:N, so no authentication or user interaction is required. Any device exposing this service to an untrusted network is exposed.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.70334, 99.35th percentile) and the advisory references are tagged Exploit, indicating public exploit material exists. No ransomware group usage is documented.
What to do
- Apply the Realtek vendor patch referenced in the Realtek APRouter SDK advisory (CVE-2021-35392_35395) or the vendor update page; if no patch exists for your device, contact the OEM.
- Disable UPnP/SSDP and the WiFi Simple Config service on affected devices where not strictly required.
- Block inbound UPnP/SSDP (UDP 1900, TCP 2869/5000 as applicable) at network boundaries and segment IoT/embedded devices away from trusted networks.
- Replace or isolate end-of-life devices running the affected SDK if the vendor no longer provides firmware updates.
Detection
- Monitor for malformed or oversized UPnP SUBSCRIBE/UNSUBSCRIBE requests with abnormal Callback headers targeting the device's UPnP port.
- Alert on unexpected process crashes or restarts of wscd/mini_upnpd, which may indicate exploitation attempts.
- Watch for anomalous outbound connections or new listening services from embedded devices that could indicate post-exploitation code execution.
- Inventory devices exposing UPnP/SSDP and flag those running Realtek Jungle SDK versions in the affected range.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain | Broken LinkExploitThird Party Advisory |
| https://www.realtek.com/en/cu-1-en/cu-1-taiwan-en | Broken LinkPatchVendor Advisory |
| https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf | PatchVendor Advisory |
| https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain | Broken LinkExploitThird Party Advisory |
| https://www.realtek.com/en/cu-1-en/cu-1-taiwan-en | Broken LinkPatchVendor Advisory |
| https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf | PatchVendor Advisory |
Track CVE-2021-35393 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-35393), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.