Vulnerability record · CVE-2021-35395 · published 16 August 2021
CVE-2021-35395: Realtek Jungle SDK web server buffer overflow and command injection
RRealtek · Rtl819x Jungle Software Development Kit
The Realtek Jungle SDK (v2.x through v3.4.14B) ships an HTTP management interface, in both Go-Ahead 'webs' and Boa 'boa' variants, that mishandles several form parameters. Multiple stack buffer overflows (submit-url, ifname, hostname, peerPin) and command injection/execution flaws (sysCmd, peerPin) let a remote attacker run arbitrary code on affected access points. Because the SDK is widely reused by device vendors, exposure varies by product, but the underlying code is broadly insecure.
Description
Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access point. Two versions of this management interface exists: one based on Go-Ahead named webs and another based on Boa named boa. Both of them are affected by these vulnerabilities. Specifically, these binaries are vulnerable to the following issues: - stack buffer overflow in formRebootCheck due to unsafe copy of submit-url parameter - stack buffer overflow in formWsc due to unsafe copy of submit-url parameter - stack buffer overflow in formWlanMultipleAP due to unsafe copy of submit-url parameter - stack buffer overflow in formWlSiteSurvey due to unsafe copy of ifname parameter - stack buffer overflow in formStaticDHCP due to unsafe copy of hostname parameter - stack buffer overflow in formWsc due to unsafe copy of 'peerPin' parameter - arbitrary command execution in formSysCmd via the sysCmd parameter - arbitrary command injection in formWsc via the 'peerPin' parameter Exploitability of identified issues will differ based on what the end vendor/manufacturer did with the Realtek SDK webserver. Some vendors use it as-is, others add their own authentication implementation, some kept all the features from the server, some remove some of them, some inserted their own set of features. However, given that Realtek SDK implementation is full of insecure calls and that developers tends to re-use those examples in their custom code, any binary based on Realtek SDK webserver will probably contains its own set of issues on top of the Realtek ones (if kept). Successful exploitation of these issues allows remote attackers to gain arbitrary code execution on the device.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no privileges or interaction required, active KEV listing, near-maximum EPSS, and confirmed public exploit material make this an urgent remote code execution risk.
What it is
The Realtek Jungle SDK (v2.x through v3.4.14B) ships an HTTP management interface, in both Go-Ahead 'webs' and Boa 'boa' variants, that mishandles several form parameters. Multiple stack buffer overflows (submit-url, ifname, hostname, peerPin) and command injection/execution flaws (sysCmd, peerPin) let a remote attacker run arbitrary code on affected access points. Because the SDK is widely reused by device vendors, exposure varies by product, but the underlying code is broadly insecure.
Impact
An unauthenticated remote attacker can achieve arbitrary code execution on the device, giving full control of the access point and any network traffic it handles.
Attack surface
Reached over the network via the device's HTTP management interface; the CVSS vector indicates no privileges or user interaction required, though the advisory notes some vendors add their own authentication layer that could change reachability.
Exploitation
Listed in CISA KEV since 2021-11-03 with a required action deadline of 2021-11-17, and EPSS 30-day probability is 0.97961 (99.9th percentile); reference tags include Exploit and Third Party Advisory, confirming public exploit material exists.
What to do
- Apply the vendor patch per the Realtek AP-Router SDK advisory (CVE-2021-35392/35395) and any downstream device firmware updates.
- Identify all devices using the Realtek Jungle SDK and confirm with each manufacturer whether the vulnerable web server is present and patched.
- Restrict management interface access to trusted networks; do not expose the HTTP admin port to the internet.
- Disable unused web management features and, where possible, replace end-of-life devices that cannot be patched.
Detection
- Monitor HTTP requests to the management interface for the vulnerable parameters: submit-url, ifname, hostname, peerPin, and sysCmd.
- Alert on long or malformed values in those parameters that suggest buffer overflow attempts.
- Watch for command-injection patterns (shell metacharacters, encoded payloads) in requests to formSysCmd and formWsc.
- Hunt for unexpected outbound connections or process execution on access points that could indicate post-exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-35395 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Realtek AP-Router SDK Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain | Broken LinkExploitThird Party Advisory |
| https://www.realtek.com/en/cu-1-en/cu-1-taiwan-en | Broken LinkPatchVendor Advisory |
| https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf | Patch |
| https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain | Broken LinkExploitThird Party Advisory |
| https://www.realtek.com/en/cu-1-en/cu-1-taiwan-en | Broken LinkPatchVendor Advisory |
| https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf | Patch |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-35395 | US Government Resource |
Track CVE-2021-35395 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-35395), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.