What's new

Critical Realtek vulnerabilities and 374 LTS

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

reddy

Occasional Visitor
Hi,

Realtek has recently announced critical vulnerabilities affecting RT-Nxx models:
  • CVE-2021-35392, Wi-Fi Simple Config stack buffer overflow (UPnP)
  • CVE-2021-35393, Wi-Fi Simple Config heap buffer overflow (SSDP)
  • CVE-2021-35394, MP Daemon diagnostic tool command injection
  • CVE-2021-35395, management web interface multiple vulnerabilities

Does anyone know if that will be mitigated in the 374 LTS?
 
Does anyone know if that will be mitigated in the 374 LTS?
These are vulnerabilities in the Realtek SDK so none of them would apply to any Merlin/fork firmware as those are using Broadcom hardware/SDK.

The "known" effected Asus models are WL330-NUL, RT-N10E, RT-N10LX, RT-N12E and RT-N12LX.
 
Last edited:
From August 2021 to December 2022, we have observed 134 million exploit attempts in total, targeting CVE-2021-35394, with 97% of these attacks occurring after the start of August 2022.

 

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top