2021-35395 | Realtek Jungle SDK HTTP Web Server stack-based overflow
CVSS Meta Temp Score | Current Exploit Price (≈) | CTI Interest Score |
---|---|---|
6.3 | $0-$5k | 1.22 |
A vulnerability was found in Realtek Jungle SDK up to 3.4.14B and classified as critical. This issue affects an unknown functionality of the component HTTP Web Server. The manipulation of the argument url
with an unknown input leads to a memory corruption vulnerability. Using CWE to declare the problem leads to CWE-121. Impacted is confidentiality, integrity, and availability. The summary by CVE is:
Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access point. Two versions of this management interface exists: one based on Go-Ahead named webs and another based on Boa named boa. Both of them are affected by these vulnerabilities. Specifically, these binaries are vulnerable to the following issues: – stack buffer overflow in formRebootCheck due to unsafe copy of submit-url parameter – stack buffer overflow in formWsc due to unsafe copy of submit-url parameter – stack buffer overflow in formWlanMultipleAP due to unsafe copy of submit-url parameter – stack buffer overflow in formWlSiteSurvey due to unsafe copy of ifname parameter – stack buffer overflow in formStaticDHCP due to unsafe copy of hostname parameter – stack buffer overflow in formWsc due to unsafe copy of ‘peerPin’ parameter – arbitrary command execution in formSysCmd via the sysCmd parameter – arbitrary command injection in formWsc via the ‘peerPin’ parameter Exploitability of identified issues will differ based on what the end vendor/manufacturer did with the Realtek SDK webserver. Some vendors use it as-is, others add their own authentication implementation, some kept all the features from the server, some remove some of them, some inserted their own set of features. However, given that Realtek SDK implementation is full of insecure calls and that developers tends to re-use those examples in their custom code, any binary based on Realtek SDK webserver will probably contains its own set of issues on top of the Realtek ones (if kept). Successful exploitation of these issues allows remote attackers to gain arbitrary code execution on the device.
The weakness was presented 08/16/2021. It is possible to read the advisory at iot-inspector.com. The identification of this vulnerability is CVE-2021-35395 since 06/23/2021. The exploitation is known to be easy. The attack may be initiated remotely. The successful exploitation needs a simple authentication. Technical details of the vulnerability are known, but there is no available exploit. The pricing for an exploit might be around USD $0-$5k at the moment (estimation calculated on 08/18/2021).
There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.
Vendor
Name
VulDB Meta Base Score: 6.3
VulDB Meta Temp Score: 6.3
VulDB Base Score: 6.3
VulDB Temp Score: 6.3
VulDB Vector: 🔒
VulDB Reliability: 🔍
AV | AC | Au | C | I | A |
---|---|---|---|---|---|
🔍 | 🔍 | 🔍 | 🔍 | 🔍 | 🔍 |
🔍 | 🔍 | 🔍 | 🔍 | 🔍 | 🔍 |
🔍 | 🔍 | 🔍 | 🔍 | 🔍 | 🔍 |
Vector | Complexity | Authentication | Confidentiality | Integrity | Availability |
---|---|---|---|---|---|
unlock | unlock | unlock | unlock | unlock | unlock |
unlock | unlock | unlock | unlock | unlock | unlock |
unlock | unlock | unlock | unlock | unlock | unlock |
VulDB Base Score: 🔒
VulDB Temp Score: 🔒
VulDB Reliability: 🔍
Class: Memory corruption
CWE: CWE-121
ATT&CK: Unknown
Local: No
Remote: Yes
Availability: 🔒
Status: Not defined
Price Prediction: 🔍
Current Price Estimation: 🔒
0-Day | unlock | unlock | unlock | unlock |
---|---|---|---|---|
Today | unlock | unlock | unlock | unlock |
Threat Intelligence
Interest: 🔍
Active Actors: 🔍
Active APT Groups: 🔍Recommended: no mitigation known
Status: 🔍
0-Day Time: 🔒
06/23/2021 CVE assigned
08/16/2021 Advisory disclosed
08/16/2021 VulDB entry created
08/18/2021 VulDB last updateAdvisory: iot-inspector.com
Status: Confirmed
Confirmation: 🔒
CVE: CVE-2021-35395 (🔒)
Created: 08/16/2021 16:19
Updated: 08/18/2021 17:08
Changes: (2) source_cve_assigned source_cve_nvd_summary
Complete: 🔍
Download it now for free!