Security readout for executives and security teams
Plain-English summary
This flaw affects Realtek Jungle SDK code used inside some routers and IoT devices. A malformed network discovery message can trigger a heap buffer overflow in the WiFi Simple Config service. The business risk comes from supply-chain exposure: organizations may own affected devices without knowing Realtek SDK code is inside them.
Executive priority
Make this a targeted asset-management and firmware-validation priority, especially for edge and IoT devices. Urgency is higher for internet-facing or untrusted-network exposure, but the source bundle lacks severity scoring, named affected models, and confirmed exploitation.
Technical view
CVE-2021-35392 is a heap buffer overflow in the Realtek Jungle SDK v2.x through v3.4.14B WiFi Simple Config server, commonly named wscd or mini_upnpd. The issue occurs when SSDP NOTIFY messages are unsafely crafted from received M-SEARCH ST headers. UPnP and SSDP exposure are the key technical indicators.
Likely exposure
Most likely exposure is embedded routers, access points, and IoT equipment built by OEMs using the affected Realtek SDK. The CVE bundle does not identify specific downstream device models, so exposure requires vendor, firmware, or SBOM confirmation.
Exploitation context
The provided sources do not state active exploitation, and the CVE is not marked CISA KEV. The flaw is remotely reachable where the affected UPnP/SSDP WiFi Simple Config service is exposed, but exploitability details and real-world targeting are not established in the bundle.
Researcher notes
The strongest evidence is the CVE description and Realtek/IoT Inspector references. Missing data includes CVSS, CWE mapping, downstream affected products, exploit status, and exact fixed versions. Avoid broad product claims without firmware-level confirmation.
Mitigation direction
- Check Realtek and device-vendor advisories for fixed SDK or firmware guidance.
- Update affected device firmware when the vendor confirms CVE-2021-35392 remediation.
- Prioritize devices exposing UPnP, SSDP, wscd, or mini_upnpd on untrusted networks.
- Remove or replace unsupported devices if no vendor fix is available.
- Do not assume a device is unaffected solely because it is not Realtek-branded.
Validation and detection
- Inventory routers, access points, and IoT devices for Realtek SDK usage.
- Check firmware documentation, SBOMs, or vendor advisories for Jungle SDK versions v2.x through v3.4.14B.
- Identify devices running WiFi Simple Config, UPnP, SSDP, wscd, or mini_upnpd services.
- Confirm remediation status against Realtek or OEM firmware release notes.
- Document unknown firmware lineage as unresolved supply-chain exposure.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-35392 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.realtek.com/en/cu-1-en/cu-1-taiwan-enCVE reference · x_refsource_MISC
- https://www.realtek.com/images/safe-report/Realtek_APRouter_SDK_Advisory-CVE-2021-35392_35395.pdfCVE reference · x_refsource_MISC
- https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chainCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
