Skip to content
COOEY

EXPOSURES › CVE-2021-35395

CVE-2021-35395

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-35395 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

Realtek AP-Router SDK HTTP web server boa suffered a buffer overflow vulnerability allowing denial-of-service via unsafe parameter copying.

The Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability that allows attackers to submit overly long parameters, leading to a denial-of-service attack. DIB organizations should care because Realtek has a history of high-severity remote code execution and memory corruption flaws, indicating inconsistent input validation and memory safety practices across its product lines. Organizations relying on Realtek components must implement defense-in-depth controls and ensure timely patching to mitigate these risks.

Shame score — A buffer overflow vulnerability in a widely used SDK indicates negligent input validation and memory safety practices, which is avoidable and poses a significant risk to systems relying on Realtek components.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some overly long parameters submitted in the form that lead to denial-of-service (DoS).

SENTIMENT · TRUSTED SOURCES
synthesis neutral +0.00
No coverage found for CVE-2021-35395 in provided sources.
cooey ↗ neutral +0.00
Neutral; only factual CVE description provided.
"Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some overly long parameters submitted in the form that lead to denial-of-service (DoS)."
CISA ↗ neutral +0.00
Irrelevant; discusses Siemens S7 PLCs, not Realtek.
"Defending Against an Active Threat to Siemens S7 Series PLCs | CISA"
www.cvefind.com ↗ neutral +0.00
Irrelevant; generic CVE database site.
"CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws."
Irrelevant; discusses Cisco Secure Workload Software, not Realtek.
"Cisco Secure Workload Software Security Hardening Release: August 2026"
techcrunch.com ↗ neutral +0.00
Irrelevant; discusses T-Mobile and Chinese hackers, not Realtek.
"T-Mobile 'chopped a cable' to expel Chinese hackers from its network"
www.arista.com ↗ neutral +0.00
Irrelevant; site error page.
"Client Challenge A required part of this site couldn't load."
app.opencve.io ↗ neutral +0.00
Irrelevant; generic CVE search site.
"CVEs and Security Vulnerabilities - OpenCVE"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.