โ† Back

Rtl819x Jungle Software Development Kit

rtl819x_jungle_software_development_kit

Vendor: Realtek โ€ข 23 CVEs

CVEs (23)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Level1
Realtek
2Rtl819x Jungle Software Development Kit
Wbr 6013 Firmware
Nov 4, 2025
Jul 8, 2024
N/Aยท v4
7.2 HIGHยท v3
N/Aยท v2
A heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted .dat file can lead to arbitrary code execution. An...Show more
A heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted .dat file can lead to arbitrary code execution. An attacker can upload a malicious file to trigger this vulnerability.Show less
2Level1
Realtek
2Rtl819x Jungle Software Development Kit
Wbr 6013 Firmware
Nov 4, 2025
Jul 8, 2024
N/Aยท v4
7.2 HIGHยท v3
N/Aยท v2
Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker ca...Show more
Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related to the `localPin` request's parameter.Show less
2Level1
Realtek
2Rtl819x Jungle Software Development Kit
Wbr 6013 Firmware
Nov 4, 2025
Jul 8, 2024
N/Aยท v4
7.2 HIGHยท v3
N/Aยท v2
Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker ca...Show more
Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related to the `peerPin` request's parameter.Show less
2Level1
Realtek
2Rtl819x Jungle Software Development Kit
Wbr 6013 Firmware
Nov 4, 2025
Jul 8, 2024
N/Aยท v4
7.2 HIGHยท v3
N/Aยท v2
Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker ca...Show more
Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related to the `targetAPSsid` request's parameter.Show less
2Level1
Realtek
2Rtl819x Jungle Software Development Kit
Wbr 6013 Firmware
Nov 4, 2025
Jul 8, 2024
N/Aยท v4
7.2 HIGHยท v3
N/Aยท v2
A stack-based buffer overflow vulnerability exists in the boa getInfo functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can se...Show more
A stack-based buffer overflow vulnerability exists in the boa getInfo functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger this vulnerability.Show less
2Level1
Realtek
2Rtl819x Jungle Software Development Kit
Wbr 6013 Firmware
Nov 4, 2025
Jul 8, 2024
N/Aยท v4
7.2 HIGHยท v3
N/Aยท v2
Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker c...Show more
Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This stack-based buffer overflow is related to the `entry_name` request's parameter.Show less
2Level1
Realtek
2Rtl819x Jungle Software Development Kit
Wbr 6013 Firmware
Nov 4, 2025
Jul 8, 2024
N/Aยท v4
7.2 HIGHยท v3
N/Aยท v2
Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker c...Show more
Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This stack-based buffer overflow is related to the `comment` request's parameter.Show less
2Level1
Realtek
2Rtl819x Jungle Software Development Kit
Wbr 6013 Firmware
Nov 4, 2025
Jul 8, 2024
N/Aยท v4
7.2 HIGHยท v3
N/Aยท v2
Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to remote code executi...Show more
Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This stack-based buffer overflow is related to the `AdvDefaultPreference` request's parameter.Show less
2Level1
Realtek
2Rtl819x Jungle Software Development Kit
Wbr 6013 Firmware
Nov 4, 2025
Jul 8, 2024
N/Aยท v4
7.2 HIGHยท v3
N/Aยท v2
Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to remote code executi...Show more
Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This stack-based buffer overflow is related to the `interfacename` request's parameter.Show less
2Level1
Realtek
2Rtl819x Jungle Software Development Kit
Wbr 6013 Firmware
Nov 4, 2025
Jul 8, 2024
N/Aยท v4
7.2 HIGHยท v3
N/Aยท v2
A stack-based buffer overflow vulnerability exists in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can se...Show more
A stack-based buffer overflow vulnerability exists in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send a series of HTTP requests to trigger this vulnerability.Show less
2Level1
Realtek
2Rtl819x Jungle Software Development Kit
Wbr 6013 Firmware
Nov 4, 2025
Jul 8, 2024
N/Aยท v4
7.2 HIGHยท v3
N/Aยท v2
A stack-based buffer overflow vulnerability exists in the boa rollback_control_code functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution...Show more
A stack-based buffer overflow vulnerability exists in the boa rollback_control_code functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.Show less
2Level1
Realtek
2Rtl819x Jungle Software Development Kit
Wbr 6013 Firmware
Nov 4, 2025
Jul 8, 2024
N/Aยท v4
7.2 HIGHยท v3
N/Aยท v2
A stack-based buffer overflow vulnerability exists in the boa formFilter functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary code execution. An attacker...Show more
A stack-based buffer overflow vulnerability exists in the boa formFilter functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.Show less
2Level1
Realtek
2Rtl819x Jungle Software Development Kit
Wbr 6013 Firmware
Nov 4, 2025
Jul 8, 2024
N/Aยท v4
7.2 HIGHยท v3
N/Aยท v2
A stack-based buffer overflow vulnerability exists in the boa formDnsv6 functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacke...Show more
A stack-based buffer overflow vulnerability exists in the boa formDnsv6 functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.Show less
2Level1
Realtek
2Rtl819x Jungle Software Development Kit
Wbr 6013 Firmware
Nov 4, 2025
Jul 8, 2024
N/Aยท v4
7.2 HIGHยท v3
N/Aยท v2
A stack-based buffer overflow vulnerability exists in the boa set_RadvdPrefixParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to remote code execution. An...Show more
A stack-based buffer overflow vulnerability exists in the boa set_RadvdPrefixParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.Show less
2Level1
Realtek
2Rtl819x Jungle Software Development Kit
Wbr 6013 Firmware
Nov 4, 2025
Jul 8, 2024
N/Aยท v4
8.8 HIGHยท v3
N/Aยท v2
A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network request can lead to CSRF. An attacker can send an HTTP...Show more
A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network request can lead to CSRF. An attacker can send an HTTP request to trigger this vulnerability.Show less
2Level1
Realtek
2Rtl819x Jungle Software Development Kit
Wbr 6013 Firmware
Nov 4, 2025
Jul 8, 2024
N/Aยท v4
7.2 HIGHยท v3
N/Aยท v2
An integer overflow vulnerability exists in the boa updateConfigIntoFlash functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary code execution. An attacker...Show more
An integer overflow vulnerability exists in the boa updateConfigIntoFlash functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.Show less
2Level1
Realtek
2Rtl819x Jungle Software Development Kit
Wbr 6013 Firmware
Nov 4, 2025
Jul 8, 2024
N/Aยท v4
7.2 HIGHยท v3
N/Aยท v2
A stack-based buffer overflow vulnerability exists in the boa setRepeaterSsid functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An a...Show more
A stack-based buffer overflow vulnerability exists in the boa setRepeaterSsid functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can lead to arbitrary code execution. An attacker can send a sequence of requests to trigger this vulnerability.Show less
2Level1
Realtek
2Rtl819x Jungle Software Development Kit
Wbr 6013 Firmware
Nov 4, 2025
Jul 8, 2024
N/Aยท v4
7.2 HIGHยท v3
N/Aยท v2
A stack-based buffer overflow vulnerability exists in the boa formRoute functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can...Show more
A stack-based buffer overflow vulnerability exists in the boa formRoute functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.Show less
2Level1
Realtek
2Rtl819x Jungle Software Development Kit
Wbr 6013 Firmware
Nov 4, 2025
Jul 8, 2024
N/Aยท v4
7.2 HIGHยท v3
N/Aยท v2
A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network packets can lead to arbitrary firmware update. An attacker can provide a malic...Show more
A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network packets can lead to arbitrary firmware update. An attacker can provide a malicious file to trigger this vulnerability.Show less
1Realtek
1Rtl819x Jungle Software Development Kit
Nov 7, 2025
Aug 16, 2021
N/Aยท v4
9.8 CRITICALยท v3
10.0 HIGHยท v2
Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access point. Two versions of this management interface exists: one based on Go...Show more
Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access point. Two versions of this management interface exists: one based on Go-Ahead named webs and another based on Boa named boa. Both of them are affected by these vulnerabilities. Specifically, these binaries are vulnerable to the following issues: - stack buffer overflow in formRebootCheck due to unsafe copy of submit-url parameter - stack buffer overflow in formWsc due to unsafe copy of submit-url parameter - stack buffer overflow in formWlanMultipleAP due to unsafe copy of submit-url parameter - stack buffer overflow in formWlSiteSurvey due to unsafe copy of ifname parameter - stack buffer overflow in formStaticDHCP due to unsafe copy of hostname parameter - stack buffer overflow in formWsc due to unsafe copy of 'peerPin' parameter - arbitrary command execution in formSysCmd via the sysCmd parameter - arbitrary command injection in formWsc via the 'peerPin' parameter Exploitability of identified issues will differ based on what the end vendor/manufacturer did with the Realtek SDK webserver. Some vendors use it as-is, others add their own authentication implementation, some kept all the features from the server, some remove some of them, some inserted their own set of features. However, given that Realtek SDK implementation is full of insecure calls and that developers tends to re-use those examples in their custom code, any binary based on Realtek SDK webserver will probably contains its own set of issues on top of the Realtek ones (if kept). Successful exploitation of these issues allows remote attackers to gain arbitrary code execution on the device.Show less