RW
RiskWire Real-time vulnerability intelligence
This week Pricing Live dashboard
Critical KEV-listed

CVE-2021-35394

ClingSTUN Botnet Exploits Multiple IoT Vulnerabilities via STUN Protocol

Vendor / product: Realtek Jungle SDK, Hytec Inter HWL-2511-SS
Public PoC: Yes
First tracked by RiskWire: 2026-10-07

CISA KEV catalog

Added to KEV
Federal remediation due
2021-12-24 (1748 days overdue)
Ransomware campaign use
Unknown
CISA description
RealTek Jungle SDK contains multiple memory corruption vulnerabilities which can allow an attacker to perform remote code execution.
Required action
Apply updates per vendor instructions.

Sources & citations (22)

+2 more sources

References

See CVE-2021-35394 in context

RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.

Book a 20-min demo →