Skip to content
COOEY

EXPOSURES › CVE-2021-35394

CVE-2021-35394

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-12-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-35394 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Realtek Jungle SDK shipped with multiple memory corruption flaws enabling remote code execution.

The Realtek Jungle SDK contained multiple memory corruption vulnerabilities allowing attackers to execute arbitrary code remotely. DIB organizations must treat Realtek SDKs as high-risk components requiring strict input validation and memory safety controls, as the vendor has a documented history of shipping similar high-severity flaws. Failure to patch or isolate these SDKs exposes systems to remote compromise and violates CMMC/NIST 800-171 requirements for managing known vulnerabilities.

Shame score — A major semiconductor vendor repeatedly shipped high-severity RCE and memory corruption flaws in its SDKs and router firmware, indicating inconsistent input validation and memory safety practices that require defense-in-depth controls.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an attacker to perform remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.