References https://nvd.nist.gov/vuln/detail/cve-2021-35395 https://www.sentinelone.com/vulnerability-database/cve-2021-35395/ https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-35395 https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf https://github.com/advisories/GHSA-qrv5-8v43-rrgf https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain https://fortiguard.fortinet.com/threat-signal-report/5068 https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2023-012/ https://www.extrahop.com/resources/detections/cve-2021-35395-realtek-sdk-exploit-attempt https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=33272 https://www.helpnetsecurity.com/2021/08/24/cve-2021-35395-exploitation/ https://pentest-tools.com/vulnerabilities-exploits/realtek-jungle-sdk-arbitrary-command-injection_2819 https://www.sonicwall.com/blog/realtek-jungle-sdk-remote-code-execution
Related VulnerabilitiesPoCCVE-2019-19822: TOTOLINK/Realtek Routers - Information DisclosurePoCCVE-2019-19823: TOTOLINK/Realtek Routers - Information DisclosurePoCCVE-2019-19825: TOTOLINK/Realtek Routers - CAPTCHA BypassPoCCVE-2019-19824: TOTOLINK Realtek SD Routers - Remote Command InjectionPoCCVE-2021-35395: RealTek Jungle SDK - Arbitrary Command InjectionPoCCVE-2021-35394: RealTek AP Router SDK - Arbitrary Command InjectionRealtek rtl819x Jungle formIpQoS 栈缓冲区溢出漏洞Realtek eCOS SDK CVE-2022-27255缓冲区溢出漏洞Realtek Jungle SDK CVE-2021-35393栈缓冲区溢出漏洞Realtek Jungle SDK CVE-2021-35392栈缓冲区溢出漏洞REALTEK 1GE+Wifi formPing 远程命令执行Realtek GPON router - Command InjectionRealtek RTL8111EP-CG/RTL8111FP-CG - Use of Hard-coded Credentials