← Vulnerability feed

Vulnerability record · CVE-2021-35394 · published 16 August 2021

CVE-2021-35394: Realtek Jungle SDK MP Daemon command injection and memory corruption

RRealtek · Rtl819x Jungle Software Development Kit

The Realtek Jungle SDK (v2.x through v3.4.14B) ships a diagnostic tool called MP Daemon, usually compiled as the UDPServer binary, which contains multiple memory corruption flaws and an OS command injection flaw. Because the daemon is reachable over the network without credentials, it exposes affected routers and IoT devices to remote code execution.

9.8 CVSS 3.1 Critical CISA KEV since 10 Dec 2021 EPSS 100% · top 0.1% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
9References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated remote code execution, KEV listing and near-certain EPSS probability make this an urgent patch target.

What it is

The Realtek Jungle SDK (v2.x through v3.4.14B) ships a diagnostic tool called MP Daemon, usually compiled as the UDPServer binary, which contains multiple memory corruption flaws and an OS command injection flaw. Because the daemon is reachable over the network without credentials, it exposes affected routers and IoT devices to remote code execution.

Impact

A remote unauthenticated attacker can execute arbitrary commands on the device, gaining full control of the affected system and its network position.

Attack surface

Reached over the network via the UDPServer/MP Daemon service; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.

Exploitation

Listed in CISA KEV since 2021-12-10 with a required action to apply vendor updates, and EPSS shows a 30-day probability of 0.99861 (99.9th percentile), indicating active exploitation. Reference tags include Exploit and Patch advisories.

What to do

  • Apply the Realtek vendor patch per the APRouter SDK advisory covering CVE-2021-35392 through CVE-2021-35395.
  • If the device cannot be patched, disable or block the MP Daemon/UDPServer service and restrict its UDP port to trusted management networks only.
  • Segment IoT and router devices from production networks and block inbound access to their management and diagnostic services at the perimeter.
  • Inventory devices using the Realtek Jungle SDK and track vendor firmware updates, since the SDK is embedded in third-party products.
  • Monitor for vendor follow-up advisories, as the original vendor and third-party links are reported broken.

Detection

  • Monitor network traffic to the UDPServer/MP Daemon UDP port for anomalous or oversized payloads and unexpected command strings.
  • Alert on unexpected outbound connections or process execution from router/IoT firmware, which may indicate post-exploitation command execution.
  • Use the CISA KEV entry and EPSS score to prioritize scanning and patch verification for devices running the Realtek Jungle SDK.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-35394 to the Known Exploited Vulnerabilities catalog on 10 December 2021 as "Realtek Jungle SDK Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 December 2021.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-35394 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-35395Realtek Jungle SDK web server buffer overflow and command injectionThe Realtek Jungle SDK (v2.x through v3.4.14B) ships an HTTP management interface, in both Go-Ahead 'webs' and Boa 'boa' variants, that mishandles se…KEVEPSS 98%analysed9.8CVE-2021-35393Realtek Jungle SDK wscd UPnP SUBSCRIBE Callback stack buffer overflowThe Realtek Jungle SDK (v2.x up to v3.4.14B) ships a WiFi Simple Config server (wscd/mini_upnpd) that implements UPnP and SSDP. It parses the UPnP SU…EPSS 70%analysed8.8CVE-2023-47677Realtek rtl819x jungle software development kit cross-site request forgery vulnerabilityA cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially …EPSS 0.37%7.5CVE-2021-35392Realtek Jungle SDK wscd SSDP heap buffer overflowThe Realtek Jungle SDK (v2.x up to v3.4.14B) ships a WiFi Simple Config server (wscd or mini_upnpd) that implements UPnP and SSDP. It writes past a h…EPSS 83%analysed7.2CVE-2023-50382Realtek rtl819x jungle software development kit os command injection vulnerabilityThree os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series o…EPSS 1.9%7.2CVE-2023-50383Realtek rtl819x jungle software development kit os command injection vulnerabilityThree os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series o…EPSS 1.9%7.2CVE-2024-21778Realtek rtl819x jungle software development kit heap-based buffer overflow vulnerabilityA heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realtek rtl819x Jungle SDK v3.4.11.…EPSS 0.94%7.2CVE-2023-50243Realtek rtl819x jungle software development kit stack-based buffer overflow vulnerabilityTwo stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted s…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2021-35394), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.