TROYANOSYVIRUS
Volver a CVEs

CVE-2021-35394

CRITICALCISA KEV
9.8

Descripcion

Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.

Detalles CVE

Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado8/16/2021
Ultima modificacion11/7/2025
Fuentekev
Avistamientos honeypot0

CISA KEV

VendedorRealtek
ProductoJungle Software Development Kit (SDK)
Nombre vulnerabilidadRealtek Jungle SDK Remote Code Execution Vulnerability
Fecha inclusion KEV2021-12-10
Fecha limite remediacion2021-12-24
Uso en ransomwareUnknown

Productos afectados

realtek:rtl819x_jungle_software_development_kit

Debilidades (CWE)

CWE-78

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.