Threat Intelligence / CVE / CVE-2021-35394

CVE-2021-35394

CISA KEV
CVSS 9.8 (CRITICAL) · EPSS 99.9% · Priority 9/10 · Published 2021-08-16

As of 2025-10-21, CVE-2021-35394 is a CVSS 9.8 (CRITICAL-severity) vulnerability. CISA KEV-listed (known exploited); Public exploit code available; Nuclei detection template exists. EPSS exploitation probability 99.9%. Threadlinqs Intelligence tracks 1 threat exploiting it.

Last updated: 2025-10-21

Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.

CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

CWE-78

Exploitation status

CISA KEV-listed (known exploited) · public exploit code available · nuclei detection template exists

Threats tracking this CVE

References

Full detection coverage & IOCs for threats exploiting CVE-2021-35394 are available via the Threadlinqs MCP server (Purple tier). View plans →

← all vulnerabilities · Markdown version · Threadlinqs Intelligence

Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.