CVE-2021-35392 is a critical heap buffer overflow vulnerability in Realtek Jungle SDK versions up to v3.4.14B, specifically within its 'WiFi Simple Config' server (wscd or mini_upnpd) due to unsafe SSDP NOTIFY message crafting. This vulnerability carries a high CVSS score of 7.5, indicating it can be exploited remotely with low complexity, leading to a complete denial of service. While no public exploit code is readily available, the vulnerability has garnered significant community discussion and media coverage, with reports confirming active exploitation shortly after disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0, <= 3.4.14bCPE matchmatch criteria | cpe:2.3:a:realtek:rtl819x_jungle_software_development_kit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.