Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-35395 PoC — Realtek Jungle SDK 安全漏洞

Source
Associated Vulnerability
Title:Realtek Jungle SDK 安全漏洞 (CVE-2021-35395)
Description:Realtek Jungle SDK是中国瑞昱半导体(Realtek)公司的提供了一个 HTTP Web 服务器,公开了一个管理接口,可用于配置接入点。 Realtek Jungle SDK 中存在安全漏洞,该漏洞源于产品的配置管理接口未能正确处理URL参数,攻击者可通过该漏洞导致缓冲区错误。以下产品及版本受到影响:Realtek Jungle SDK v2.x 至 v3.4.14B 版本。
Description
There is a command injection vulnerability on the "formWsc" page of the management interface. Successful exploitation of this vulnerability could lead to remote code execution and compromise of the affected system.
File Snapshot

id: CVE-2021-35395 info: name: RealTek Jungle SDK - Arbitrary Command Injection author: king-al ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.