Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.
Is CVE-2021-35394 exploited?
Listed in the CISA KEV catalog on 2021-12-10.
Federal remediation due 2021-12-24.
Past that date by 1746 days.
EPSS puts exploitation in the next 30 days at 99.9%.
Public exploit code: none found in monitored sources.