{"cveID":"CVE-2021-35394","vendorProject":"Realtek","product":"Jungle Software Development Kit (SDK)","vulnerabilityName":"Realtek Jungle SDK Remote Code Execution Vulnerability","dateAdded":"2021-12-10","shortDescription":"RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an attacker to perform remote code execution.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2021-12-24","knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2021-35394","cwes":["CWE-78","CWE-138"],"year":2021,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2021-35394","technique":"T1190","technique_name_at_mapping":"Exploit Public-Facing Application","mapping_type":"exploitation_technique","capability_group":"code_execution","comments":"The vulnerability in Realtek Jungle chipsets is exploited by remote, unauthenticated attackers using UDP packets to a server on port 9034, enabling remote execution of arbitrary commands. The attack involves injecting a shell command that downloads and executes a shell script on the compromised device. This script downloads binaries for various CPU architectures, such as ARM, MIPS, and SuperH, primarily from the Mirai malware family, turning the device into a botnet node.\n\nThe attack script connects to a malicious IP to download and execute malware, with threats mainly from Mirai, Gafgyt, and Mozi families. It also includes a new DDoS botnet called RedGoBot, developed in Golang. The script uses wget and curl to download botnet clients for different processor architectures. RedGoBot can perform DDoS attacks on various protocols, including HTTP, ICMP, TCP, UDP, VSE, and OpenVPN, upon receiving commands from the threat operator. Additionally, injected commands can write binary payloads to files for execution or reboot the targeted server to cause denial of service.","references":["https://unit42.paloaltonetworks.com/realtek-sdk-vulnerability/","https://blogs.juniper.net/en-us/threat-research/realtek-cve-2021-35394-exploited-in-the-wild"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-35394","technique":"T1059","technique_name_at_mapping":"Command and Scripting Interpreter","mapping_type":"primary_impact","capability_group":"code_execution","comments":"The vulnerability in Realtek Jungle chipsets is exploited by remote, unauthenticated attackers using UDP packets to a server on port 9034, enabling remote execution of arbitrary commands. The attack involves injecting a shell command that downloads and executes a shell script on the compromised device. This script downloads binaries for various CPU architectures, such as ARM, MIPS, and SuperH, primarily from the Mirai malware family, turning the device into a botnet node.\n\nThe attack script connects to a malicious IP to download and execute malware, with threats mainly from Mirai, Gafgyt, and Mozi families. It also includes a new DDoS botnet called RedGoBot, developed in Golang. The script uses wget and curl to download botnet clients for different processor architectures. RedGoBot can perform DDoS attacks on various protocols, including HTTP, ICMP, TCP, UDP, VSE, and OpenVPN, upon receiving commands from the threat operator. Additionally, injected commands can write binary payloads to files for execution or reboot the targeted server to cause denial of service.","references":["https://unit42.paloaltonetworks.com/realtek-sdk-vulnerability/","https://blogs.juniper.net/en-us/threat-research/realtek-cve-2021-35394-exploited-in-the-wild"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-35394","technique":"T1071.001","technique_name_at_mapping":"Web Protocols","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"The vulnerability in Realtek Jungle chipsets is exploited by remote, unauthenticated attackers using UDP packets to a server on port 9034, enabling remote execution of arbitrary commands. The attack involves injecting a shell command that downloads and executes a shell script on the compromised device. This script downloads binaries for various CPU architectures, such as ARM, MIPS, and SuperH, primarily from the Mirai malware family, turning the device into a botnet node.\n\nThe attack script connects to a malicious IP to download and execute malware, with threats mainly from Mirai, Gafgyt, and Mozi families. It also includes a new DDoS botnet called RedGoBot, developed in Golang. The script uses wget and curl to download botnet clients for different processor architectures. RedGoBot can perform DDoS attacks on various protocols, including HTTP, ICMP, TCP, UDP, VSE, and OpenVPN, upon receiving commands from the threat operator. Additionally, injected commands can write binary payloads to files for execution or reboot the targeted server to cause denial of service.","references":["https://unit42.paloaltonetworks.com/realtek-sdk-vulnerability/","https://blogs.juniper.net/en-us/threat-research/realtek-cve-2021-35394-exploited-in-the-wild"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-35394","technique":"T1105","technique_name_at_mapping":"Ingress Tool Transfer","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"The vulnerability in Realtek Jungle chipsets is exploited by remote, unauthenticated attackers using UDP packets to a server on port 9034, enabling remote execution of arbitrary commands. The attack involves injecting a shell command that downloads and executes a shell script on the compromised device. This script downloads binaries for various CPU architectures, such as ARM, MIPS, and SuperH, primarily from the Mirai malware family, turning the device into a botnet node.\n\nThe attack script connects to a malicious IP to download and execute malware, with threats mainly from Mirai, Gafgyt, and Mozi families. It also includes a new DDoS botnet called RedGoBot, developed in Golang. The script uses wget and curl to download botnet clients for different processor architectures. RedGoBot can perform DDoS attacks on various protocols, including HTTP, ICMP, TCP, UDP, VSE, and OpenVPN, upon receiving commands from the threat operator. Additionally, injected commands can write binary payloads to files for execution or reboot the targeted server to cause denial of service.","references":["https://unit42.paloaltonetworks.com/realtek-sdk-vulnerability/","https://blogs.juniper.net/en-us/threat-research/realtek-cve-2021-35394-exploited-in-the-wild"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-35394","technique":"T1496","technique_name_at_mapping":"Resource Hijacking","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"The vulnerability in Realtek Jungle chipsets is exploited by remote, unauthenticated attackers using UDP packets to a server on port 9034, enabling remote execution of arbitrary commands. The attack involves injecting a shell command that downloads and executes a shell script on the compromised device. This script downloads binaries for various CPU architectures, such as ARM, MIPS, and SuperH, primarily from the Mirai malware family, turning the device into a botnet node.\n\nThe attack script connects to a malicious IP to download and execute malware, with threats mainly from Mirai, Gafgyt, and Mozi families. It also includes a new DDoS botnet called RedGoBot, developed in Golang. The script uses wget and curl to download botnet clients for different processor architectures. RedGoBot can perform DDoS attacks on various protocols, including HTTP, ICMP, TCP, UDP, VSE, and OpenVPN, upon receiving commands from the threat operator. Additionally, injected commands can write binary payloads to files for execution or reboot the targeted server to cause denial of service.","references":["https://unit42.paloaltonetworks.com/realtek-sdk-vulnerability/","https://blogs.juniper.net/en-us/threat-research/realtek-cve-2021-35394-exploited-in-the-wild"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-35394","technique":"T1499","technique_name_at_mapping":"Endpoint Denial of Service","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"The vulnerability in Realtek Jungle chipsets is exploited by remote, unauthenticated attackers using UDP packets to a server on port 9034, enabling remote execution of arbitrary commands. The attack involves injecting a shell command that downloads and executes a shell script on the compromised device. This script downloads binaries for various CPU architectures, such as ARM, MIPS, and SuperH, primarily from the Mirai malware family, turning the device into a botnet node.\n\nThe attack script connects to a malicious IP to download and execute malware, with threats mainly from Mirai, Gafgyt, and Mozi families. It also includes a new DDoS botnet called RedGoBot, developed in Golang. The script uses wget and curl to download botnet clients for different processor architectures. RedGoBot can perform DDoS attacks on various protocols, including HTTP, ICMP, TCP, UDP, VSE, and OpenVPN, upon receiving commands from the threat operator. Additionally, injected commands can write binary payloads to files for execution or reboot the targeted server to cause denial of service.","references":["https://unit42.paloaltonetworks.com/realtek-sdk-vulnerability/","https://blogs.juniper.net/en-us/threat-research/realtek-cve-2021-35394-exploited-in-the-wild"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-35394","technique":"T1569.002","technique_name_at_mapping":"Service Execution","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"The vulnerability in Realtek Jungle chipsets is exploited by remote, unauthenticated attackers using UDP packets to a server on port 9034, enabling remote execution of arbitrary commands. The attack involves injecting a shell command that downloads and executes a shell script on the compromised device. This script downloads binaries for various CPU architectures, such as ARM, MIPS, and SuperH, primarily from the Mirai malware family, turning the device into a botnet node.\n\nThe attack script connects to a malicious IP to download and execute malware, with threats mainly from Mirai, Gafgyt, and Mozi families. It also includes a new DDoS botnet called RedGoBot, developed in Golang. The script uses wget and curl to download botnet clients for different processor architectures. RedGoBot can perform DDoS attacks on various protocols, including HTTP, ICMP, TCP, UDP, VSE, and OpenVPN, upon receiving commands from the threat operator. Additionally, injected commands can write binary payloads to files for execution or reboot the targeted server to cause denial of service.","references":["https://unit42.paloaltonetworks.com/realtek-sdk-vulnerability/","https://blogs.juniper.net/en-us/threat-research/realtek-cve-2021-35394-exploited-in-the-wild"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1059","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Command and Scripting Interpreter","name_at_mapping":"Command and Scripting Interpreter","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":95,"has_detection_strategy":true},{"id":"T1071.001","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Web Protocols","name_at_mapping":"Web Protocols","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":42,"has_detection_strategy":true},{"id":"T1105","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Ingress Tool Transfer","name_at_mapping":"Ingress Tool Transfer","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":87,"has_detection_strategy":true},{"id":"T1190","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploit Public-Facing Application","name_at_mapping":"Exploit Public-Facing Application","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":149,"has_detection_strategy":true},{"id":"T1496","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Resource Hijacking","name_at_mapping":"Resource Hijacking","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":13,"has_detection_strategy":true},{"id":"T1499","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Endpoint Denial of Service","name_at_mapping":"Endpoint Denial of Service","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":3,"has_detection_strategy":true},{"id":"T1569.002","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Service Execution","name_at_mapping":"Service Execution","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":43,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}