← Vulnerability feed

Vulnerability record · CVE-2023-50383 · published 8 July 2024

CVE-2023-50383: Realtek rtl819x jungle software development kit os command injection vulnerability

RRealtek · Rtl819x Jungle Software Development Kit

Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related to the `localPin` request's parameter.

7.2 CVSS 3.1 High EPSS 1.9% · top 20.8% CWE-78 · OS command injection
7.2CVSS 3.1 base score
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related to the `localPin` request's parameter.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-50383 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-35394Realtek Jungle SDK MP Daemon command injection and memory corruptionThe Realtek Jungle SDK (v2.x through v3.4.14B) ships a diagnostic tool called MP Daemon, usually compiled as the UDPServer binary, which contains mul…KEVEPSS 100%analysed9.8CVE-2021-35395Realtek Jungle SDK web server buffer overflow and command injectionThe Realtek Jungle SDK (v2.x through v3.4.14B) ships an HTTP management interface, in both Go-Ahead 'webs' and Boa 'boa' variants, that mishandles se…KEVEPSS 98%analysed9.8CVE-2023-46685Level1 wbr-6013 firmware hard-coded password vulnerabilityA hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially cra…EPSS 1.0%9.8CVE-2021-35393Realtek Jungle SDK wscd UPnP SUBSCRIBE Callback stack buffer overflowThe Realtek Jungle SDK (v2.x up to v3.4.14B) ships a WiFi Simple Config server (wscd/mini_upnpd) that implements UPnP and SSDP. It parses the UPnP SU…EPSS 70%analysed8.8CVE-2023-47677Realtek rtl819x jungle software development kit cross-site request forgery vulnerabilityA cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially …EPSS 0.37%7.5CVE-2021-35392Realtek Jungle SDK wscd SSDP heap buffer overflowThe Realtek Jungle SDK (v2.x up to v3.4.14B) ships a WiFi Simple Config server (wscd or mini_upnpd) that implements UPnP and SSDP. It writes past a h…EPSS 83%analysed7.2CVE-2023-50382Realtek rtl819x jungle software development kit os command injection vulnerabilityThree os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series o…EPSS 1.9%7.2CVE-2024-21778Realtek rtl819x jungle software development kit heap-based buffer overflow vulnerabilityA heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realtek rtl819x Jungle SDK v3.4.11.…EPSS 0.94%

Source: NIST National Vulnerability Database (record CVE-2023-50383), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.