EXPOSURES › CVE-2021-35395
CVE-2021-35395
HIGH ⌖ ON CISA KEV · EXPLOITEDRealtek AP-Router SDK HTTP web server boa suffered a buffer overflow vulnerability allowing denial-of-service via unsafe parameter copying.
The Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability that allows attackers to submit overly long parameters, leading to a denial-of-service attack. DIB organizations should care because Realtek has a history of high-severity remote code execution and memory corruption flaws, indicating inconsistent input validation and memory safety practices across its product lines. Organizations relying on Realtek components must implement defense-in-depth controls and ensure timely patching to mitigate these risks.
Shame score — A buffer overflow vulnerability in a widely used SDK indicates negligent input validation and memory safety practices, which is avoidable and poses a significant risk to systems relying on Realtek components.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some overly long parameters submitted in the form that lead to denial-of-service (DoS).
"Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some overly long parameters submitted in the form that lead to denial-of-service (DoS)."
"Defending Against an Active Threat to Siemens S7 Series PLCs | CISA"
"CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws."
"Cisco Secure Workload Software Security Hardening Release: August 2026"
"T-Mobile 'chopped a cable' to expel Chinese hackers from its network"
"Client Challenge A required part of this site couldn't load."
"CVEs and Security Vulnerabilities - OpenCVE"