Multiple vulnerabilities in Realtek SDK



Published: 2021-08-17 | Updated: 2021-08-25
Risk Critical
Patch available YES
Number of vulnerabilities 4
CVE-ID CVE-2021-35392
CVE-2021-35395
CVE-2021-35394
CVE-2021-35393
CWE-ID CWE-121
CWE-119
CWE-78
CWE-122
Exploitation vector Network
Public exploit Vulnerability #2 is being exploited in the wild.
Vulnerability #3 is being exploited in the wild.
Vulnerable software
Subscribe
Realtek SDK
Universal components / Libraries / Software for developers

Realtek Jungle SDK
Universal components / Libraries / Software for developers

Realtek Luna SDK
Universal components / Libraries / Software for developers

Vendor Realtek

Security Bulletin

This security bulletin contains information about 4 vulnerabilities.

Updated: 25.08.2021

Updated description of vulnerability #VU55914, raised bulletin risk level from High to Critical to reflect in-the-wild exploitation.

1) Stack-based buffer overflow

EUVDB-ID: #VU55911

Risk: High

CVSSv3.1: 7.1 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-35392

CWE-ID: CWE-121 - Stack-based buffer overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to unsafe crafting of SSDP NOTIFY messages from received M-SEARCH messages ST header. A remote unauthenticated attacker can trigger stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Realtek SDK: 2.0

Realtek Jungle SDK: 3.0 - 3.4T-CT

Realtek Luna SDK: 1.3.2

External links

http://www.realtek.com/en/cu-1-en/cu-1-taiwan-en
http://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain
http://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Buffer overflow

EUVDB-ID: #VU55914

Risk: Critical

CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-35395

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in multiple parameters. A remote attacker can trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

This vulnerability affects the following parameters:

  • "submit-url" parameter in formRebootCheck/formWsc/formWlanMultipleAP
  • "ifname" parameter in formWlSiteSurvey
  • "hostname" parameter in formStaticDHCP
  • "peerPin" parameter in formWsc

Note, as of August 19 the vulnerability is being exploited in-the-wild by the Mirai botnet.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Realtek SDK: 2.0

Realtek Jungle SDK: 3.0 - 3.4T-CT

Realtek Luna SDK: 1.3.2

External links

http://www.realtek.com/en/cu-1-en/cu-1-taiwan-en
http://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain
http://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) OS Command Injection

EUVDB-ID: #VU55913

Risk: High

CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-35394

CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation within the MP Daemon diagnostic tool. A remote unauthenticated attacker can pass specially crafted data to the application and execute arbitrary OS commands on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Realtek SDK: 2.0

Realtek Jungle SDK: 3.0 - 3.4T-CT

Realtek Luna SDK: 1.3.2

External links

http://www.realtek.com/en/cu-1-en/cu-1-taiwan-en
http://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain
http://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Heap-based buffer overflow

EUVDB-ID: #VU55912

Risk: High

CVSSv3.1: 7.1 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-35393

CWE-ID: CWE-122 - Heap-based Buffer Overflow

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to unsafe parsing of the UPnP SUBSCRIBE/UNSUBSCRIBE Callback header. A remote attacker can pass specially crafted data to the application, trigger heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Realtek SDK: 2.0

Realtek Jungle SDK: 3.0 - 3.4T-CT

Realtek Luna SDK: 1.3.2

External links

http://www.realtek.com/en/cu-1-en/cu-1-taiwan-en
http://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain
http://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdf


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###