ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

65 vendors affected by severe vulnerabilities in Realtek chips

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-35393
+1 in the same advisory: …35392
Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols.

Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP protocols. The binary is usually named wscd or mini_upnpd and is the successor to miniigd. The server is vulnerable to a stack buffer overflow vulnerability that is present due to unsafe parsing of the UPnP SUBSCRIBE/UNSUBSCRIBE Callback header. Successful exploitation of this vulnerability allows remote unauthenticated attackers to gain arbitrary code execution on the affected device.

NVD description · AI analysis pending
9.8
group max
70% PoC
  • realtek rtl819x jungle software development kit
CVE-2021-35394
Remote Code Execution via Memory Corruption in Realtek Jungle SDK

Realtek's Jungle SDK, a software development kit used to build firmware for a wide range of consumer and small-office networking devices (most notably routers), contains multiple memory corruption vulnerabilities that can be triggered remotely over the network; public disclosure tied the flaws to unauthenticated network-facing components bundled with the SDK, such as its UPnP and DHCP handling. An attacker who sends crafted packets to a vulnerable device can corrupt memory and, per the associated weakness types (CWE-78 command injection, CWE-138 improper neutralization), end up executing arbitrary code or operating-system commands with the privileges of the vulnerable service, effectively taking over the device. Because the SDK is licensed into many vendors' products rather than sold as a standalone application, exposure spans numerous router and embedded-device vendors, and end users may not even know their device relies on it. Exact affected SDK version ranges and per-vendor firmware lists were not specified in the available data, so defenders should rely on the latest vendor advisories. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2021-12-10, indicating confirmed exploitation in the wild; ransomware use is unknown and no public proof-of-concept is flagged in the available data.

Do: Per CISA's required action, apply firmware updates per your device vendor's instructions, since patches are distributed by the vendors that build on the SDK rather than by Realtek directly. Identify whether your router or embedded device uses Realtek Jungle SDK-based firmware (check the vendor's model/advisory pages) and prioritize updating internet-facing devices. Where patched firmware is not yet available, restrict direct internet exposure (firewall the WAN side) and disable or limit UPnP/DHCP-related exposed services if the vendor supports doing so, while monitoring vendor advisories.

9.8100% KEV PoC
  • Realtek Jungle Software Development Kit (SDK)
mass≈ millions of devices (SDK embedded in consumer router/IoT firmware across many vendors; at least ~100,000 likely internet-exposed)
CVE-2021-35395
Multiple Stack Buffer Overflows and Command Injection in Realtek Jungle SDK Web Server

The Realtek Jungle SDK (v2.x up to v3.4.14B) ships an HTTP management web server, in both Go-Ahead ('webs') and Boa ('boa') variants, containing multiple stack buffer overflows in form handlers such as formRebootCheck, formWsc, formWlanMultipleAP, formWlSiteSurvey and formStaticDHCP, plus arbitrary command execution/injection flaws in formSysCmd and formWsc. An unauthenticated attacker triggers these by sending crafted HTTP requests with oversized submit-url, ifname, hostname or peerPin parameters, or by injecting commands via the sysCmd or peerPin parameters. Successful exploitation yields arbitrary code execution on the device, typically giving the attacker full control of the affected router, access point or IoT device. Any device whose vendor embedded the affected SDK is exposed, with public reporting linking the flaws to roughly 65 downstream vendors and nearly a million internet-visible devices. Exploitation is confirmed in the wild: the issue is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), and researchers observed Mirai botnet variants and other attackers compromising Realtek-based devices; ransomware use is unknown.

Do: Apply firmware updates from your device vendor incorporating a patched Realtek SDK (newer than v3.4.14B), per CISA's required action; since vendors ship modified builds, confirm with the manufacturer that your model is fixed. Until patched, disable remote/web-based administration or restrict the management interface (WAN-facing HTTP) with a firewall so it is not internet-exposed. Defenders should also monitor Realtek-based devices for botnet-style activity (e.g., Mirai-variant traffic), as a public PoC/advisory from IoT Inspector is available and exploitation is ongoing.

9.898% KEV PoC
  • Realtek RTL819x Jungle SDK (Realtek AP-Router SDK) HTTP web server - both Go-Ahead 'webs' and Boa 'boa' management interfaces v2.x up to v3.4.14B
  • Routers, access points and other devices built on the Realtek Jungle SDK web server firmware builds shipping the affected SDK (vendor-specific; check with your device manufacturer)
mass≈1,000,000 internet-exposed devices (public scans reported nearly a million Realtek-based devices)
Full article344 words · extracted from helpnetsecurity.com · click to collapse

A vulnerability within the Realtek RTL819xD module allows attackers to gain complete access to the device, installed operating systems and other network devices.

Realtek vulnerability

The chips supplied by Realtek are used by almost all well-known manufacturers and can be found in VoIP and wireless routers, repeaters, IP cameras, and smart lighting controls – just to name a few. The list of affected hardware manufacturers includes AsusTEK, Belkin, D-Link, Edimax, Hama, Netgear and many more.

“Our security reseachers have discovered and analyzed this vulnerability, which affects hundreds of thousands of devices. We notified Realtek, and they immediately responded and provided an appropriate patch. Manufacturers using vulnerable Wi-Fi modules are strongly encouraged to check their devices and provide security patches to their users,” said Florian Lukavsky, managing director of IoT Inspector.

Realtek vulnerability: What attackers can do

For an exploit to succeed, an attacker usually needs to be on the same Wi-Fi network. However, faulty ISP configurations also expose numerous vulnerable devices directly to the Internet.

A successful attack would provide full control of the Wi-Fi module, as well as root access to the embedded device’s operating system. In total, a dozen vulnerabilities were found in the chipset.

“There is currently far too little security awareness for devices in these categories – neither among users, nor among manufacturers, who blindly rely on components from other manufacturers in their supply chain without testing them. As a result, these components or products become an unpredictable risk,” warns Lukavsky.

According to Forrester, only 38 percent of enterprise security decision makers worldwide have sufficient policies and tools in place to properly manage IoT devices. Manufacturers are urged to implement guidelines for IoT supply chain security.

Affected versions

More details are available in the Realtek advisory, which lists these versions:

  • rtl819x-SDK-v3.2.x Series
  • rtl819x-SDK-v3.4.x Series
  • rtl819x-SDK-v3.4T Series
  • rtl819x-SDK-v3.4T-CT Series
  • rtl819x-eCos-v1.5.x Series

Fixed versions

  • Realtek SDK branch 2.x: no longer supported by Realtek
  • Realtek “Jungle” SDK: patches will be provided by Realtek and needs to be backported
  • Realtek “Luna” SDK: version 1.3.2a contains fixes

CVE IDs

  • CVE-2021-35392
  • CVE-2021-35393
  • CVE-2021-35394
  • CVE-2021-35395

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/08/16/realtek-rtl819xd-vulnerability/