Aller au contenu

Fiche vulnérabilité

CVE-2021-35393 : faille critique realtek rtl819x jungle software… (CVSS 9.8)

Description

Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usually named wscd or mini_upnpd and is the successor to miniigd. The server is vulnerable to a stack buffer overflow vulnerability that is present due to unsafe parsing of the UPnP SUBSCRIBE/UNSUBSCRIBE Callback header. Successful exploitation of this vulnerability allows remote unauthenticated attackers to gain arbitrary code execution on the affected device.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
16 août 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • realtek rtl819x jungle software development kit

Références

Rechercher une autre vulnérabilité dans la base CVE