← Vulnerability feed

Vulnerability record · CVE-2023-47677 · published 8 July 2024

CVE-2023-47677: Realtek rtl819x jungle software development kit cross-site request forgery vulnerability

RRealtek · Rtl819x Jungle Software Development Kit

A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network request can lead to CSRF. An attacker can send an HTTP request to trigger this vulnerability.

8.8 CVSS 3.1 High EPSS 0.37% · top 72.2% CWE-352 · Cross-site request forgery
8.8CVSS 3.1 base score
0.37%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network request can lead to CSRF. An attacker can send an HTTP request to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-47677 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-35394Realtek Jungle SDK MP Daemon command injection and memory corruptionThe Realtek Jungle SDK (v2.x through v3.4.14B) ships a diagnostic tool called MP Daemon, usually compiled as the UDPServer binary, which contains mul…KEVEPSS 100%analysed9.8CVE-2021-35395Realtek Jungle SDK web server buffer overflow and command injectionThe Realtek Jungle SDK (v2.x through v3.4.14B) ships an HTTP management interface, in both Go-Ahead 'webs' and Boa 'boa' variants, that mishandles se…KEVEPSS 98%analysed9.8CVE-2023-46685Level1 wbr-6013 firmware hard-coded password vulnerabilityA hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially cra…EPSS 1.0%9.8CVE-2021-35393Realtek Jungle SDK wscd UPnP SUBSCRIBE Callback stack buffer overflowThe Realtek Jungle SDK (v2.x up to v3.4.14B) ships a WiFi Simple Config server (wscd/mini_upnpd) that implements UPnP and SSDP. It parses the UPnP SU…EPSS 70%analysed7.5CVE-2021-35392Realtek Jungle SDK wscd SSDP heap buffer overflowThe Realtek Jungle SDK (v2.x up to v3.4.14B) ships a WiFi Simple Config server (wscd or mini_upnpd) that implements UPnP and SSDP. It writes past a h…EPSS 83%analysed7.2CVE-2023-50382Realtek rtl819x jungle software development kit os command injection vulnerabilityThree os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series o…EPSS 1.9%7.2CVE-2023-50383Realtek rtl819x jungle software development kit os command injection vulnerabilityThree os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series o…EPSS 1.9%7.2CVE-2024-21778Realtek rtl819x jungle software development kit heap-based buffer overflow vulnerabilityA heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realtek rtl819x Jungle SDK v3.4.11.…EPSS 0.94%

Source: NIST National Vulnerability Database (record CVE-2023-47677), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.