← Vulnerability feed

Vulnerability record · CVE-2021-35393 · published 16 August 2021

CVE-2021-35393: Realtek Jungle SDK wscd UPnP SUBSCRIBE Callback stack buffer overflow

RRealtek · Rtl819x Jungle Software Development Kit

The Realtek Jungle SDK (v2.x up to v3.4.14B) ships a WiFi Simple Config server (wscd/mini_upnpd) that implements UPnP and SSDP. It parses the UPnP SUBSCRIBE/UNSUBSCRIBE Callback header unsafely, causing a stack buffer overflow. Because the service is network-facing and unauthenticated, this is a serious pre-auth remote code execution flaw in a widely embedded SDK.

9.8 CVSS 3.1 Critical EPSS 70% · top 0.6% CWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score, v2 10.0
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usually named wscd or mini_upnpd and is the successor to miniigd. The server is vulnerable to a stack buffer overflow vulnerability that is present due to unsafe parsing of the UPnP SUBSCRIBE/UNSUBSCRIBE Callback header. Successful exploitation of this vulnerability allows remote unauthenticated attackers to gain arbitrary code execution on the affected device.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network, unauthenticated, no-interaction remote code execution, high EPSS, and public exploit references make this an urgent pre-auth RCE in widely deployed embedded firmware.

What it is

The Realtek Jungle SDK (v2.x up to v3.4.14B) ships a WiFi Simple Config server (wscd/mini_upnpd) that implements UPnP and SSDP. It parses the UPnP SUBSCRIBE/UNSUBSCRIBE Callback header unsafely, causing a stack buffer overflow. Because the service is network-facing and unauthenticated, this is a serious pre-auth remote code execution flaw in a widely embedded SDK.

Impact

A remote unauthenticated attacker can achieve arbitrary code execution on the affected device, gaining full control of the embedded system. This can lead to persistent compromise, botnet enrollment, or use as a pivot into the local network.

Attack surface

Reachable over the network via the UPnP/SSDP service (wscd or mini_upnpd) listening on the device; the CVSS vector shows AV:N/AC:L/PR:N/UI:N, so no authentication or user interaction is required. Any device exposing this service to an untrusted network is exposed.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.70334, 99.35th percentile) and the advisory references are tagged Exploit, indicating public exploit material exists. No ransomware group usage is documented.

What to do

  • Apply the Realtek vendor patch referenced in the Realtek APRouter SDK advisory (CVE-2021-35392_35395) or the vendor update page; if no patch exists for your device, contact the OEM.
  • Disable UPnP/SSDP and the WiFi Simple Config service on affected devices where not strictly required.
  • Block inbound UPnP/SSDP (UDP 1900, TCP 2869/5000 as applicable) at network boundaries and segment IoT/embedded devices away from trusted networks.
  • Replace or isolate end-of-life devices running the affected SDK if the vendor no longer provides firmware updates.

Detection

  • Monitor for malformed or oversized UPnP SUBSCRIBE/UNSUBSCRIBE requests with abnormal Callback headers targeting the device's UPnP port.
  • Alert on unexpected process crashes or restarts of wscd/mini_upnpd, which may indicate exploitation attempts.
  • Watch for anomalous outbound connections or new listening services from embedded devices that could indicate post-exploitation code execution.
  • Inventory devices exposing UPnP/SSDP and flag those running Realtek Jungle SDK versions in the affected range.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-35393 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-35394Realtek Jungle SDK MP Daemon command injection and memory corruptionThe Realtek Jungle SDK (v2.x through v3.4.14B) ships a diagnostic tool called MP Daemon, usually compiled as the UDPServer binary, which contains mul…KEVEPSS 100%analysed9.8CVE-2021-35395Realtek Jungle SDK web server buffer overflow and command injectionThe Realtek Jungle SDK (v2.x through v3.4.14B) ships an HTTP management interface, in both Go-Ahead 'webs' and Boa 'boa' variants, that mishandles se…KEVEPSS 98%analysed8.8CVE-2023-47677Realtek rtl819x jungle software development kit cross-site request forgery vulnerabilityA cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially …EPSS 0.37%7.5CVE-2021-35392Realtek Jungle SDK wscd SSDP heap buffer overflowThe Realtek Jungle SDK (v2.x up to v3.4.14B) ships a WiFi Simple Config server (wscd or mini_upnpd) that implements UPnP and SSDP. It writes past a h…EPSS 83%analysed7.2CVE-2023-50382Realtek rtl819x jungle software development kit os command injection vulnerabilityThree os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series o…EPSS 1.9%7.2CVE-2023-50383Realtek rtl819x jungle software development kit os command injection vulnerabilityThree os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series o…EPSS 1.9%7.2CVE-2024-21778Realtek rtl819x jungle software development kit heap-based buffer overflow vulnerabilityA heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realtek rtl819x Jungle SDK v3.4.11.…EPSS 0.94%7.2CVE-2023-50243Realtek rtl819x jungle software development kit stack-based buffer overflow vulnerabilityTwo stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted s…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2021-35393), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.