Vulnerability record · CVE-2021-35394 · published 16 August 2021
CVE-2021-35394: Realtek Jungle SDK MP Daemon command injection and memory corruption
RRealtek · Rtl819x Jungle Software Development Kit
The Realtek Jungle SDK (v2.x through v3.4.14B) ships a diagnostic tool called MP Daemon, usually compiled as the UDPServer binary, which contains multiple memory corruption flaws and an OS command injection flaw. Because the daemon is reachable over the network without credentials, it exposes affected routers and IoT devices to remote code execution.
Description
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated remote code execution, KEV listing and near-certain EPSS probability make this an urgent patch target.
What it is
The Realtek Jungle SDK (v2.x through v3.4.14B) ships a diagnostic tool called MP Daemon, usually compiled as the UDPServer binary, which contains multiple memory corruption flaws and an OS command injection flaw. Because the daemon is reachable over the network without credentials, it exposes affected routers and IoT devices to remote code execution.
Impact
A remote unauthenticated attacker can execute arbitrary commands on the device, gaining full control of the affected system and its network position.
Attack surface
Reached over the network via the UDPServer/MP Daemon service; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.
Exploitation
Listed in CISA KEV since 2021-12-10 with a required action to apply vendor updates, and EPSS shows a 30-day probability of 0.99861 (99.9th percentile), indicating active exploitation. Reference tags include Exploit and Patch advisories.
What to do
- Apply the Realtek vendor patch per the APRouter SDK advisory covering CVE-2021-35392 through CVE-2021-35395.
- If the device cannot be patched, disable or block the MP Daemon/UDPServer service and restrict its UDP port to trusted management networks only.
- Segment IoT and router devices from production networks and block inbound access to their management and diagnostic services at the perimeter.
- Inventory devices using the Realtek Jungle SDK and track vendor firmware updates, since the SDK is embedded in third-party products.
- Monitor for vendor follow-up advisories, as the original vendor and third-party links are reported broken.
Detection
- Monitor network traffic to the UDPServer/MP Daemon UDP port for anomalous or oversized payloads and unexpected command strings.
- Alert on unexpected outbound connections or process execution from router/IoT firmware, which may indicate post-exploitation command execution.
- Use the CISA KEV entry and EPSS score to prioritize scanning and patch verification for devices running the Realtek Jungle SDK.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-35394 to the Known Exploited Vulnerabilities catalog on 10 December 2021 as "Realtek Jungle SDK Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 December 2021.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain | Broken LinkExploitThird Party Advisory |
| https://www.realtek.com/en/cu-1-en/cu-1-taiwan-en | Broken LinkPatchVendor Advisory |
| https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf | PatchVendor Advisory |
| https://www.securityfocus.com/archive/1/534765 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain | Broken LinkExploitThird Party Advisory |
| https://www.realtek.com/en/cu-1-en/cu-1-taiwan-en | Broken LinkPatchVendor Advisory |
| https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf | PatchVendor Advisory |
| https://www.securityfocus.com/archive/1/534765 | Broken LinkThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-35394 | US Government Resource |
Track CVE-2021-35394 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-35394), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.