CVE-2014-8361 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2023-10-09.
Description
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.98% — more likely to be exploited than 100% of all CVEs |
| On CISA KEV | yes — remediate by 2023-10-09 |
| Public exploit | yes |
| Published | 2015-05-01 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Realtek SDK Improper Input Validation Vulnerability |
|---|---|
| Added | 2023-09-18 |
| Due | 2023-10-09 |
| Vendor / product | Realtek / SDK |
| Ransomware use | none reported |
Affected (40)
| Vendor | Product |
|---|---|
| aterm | w1200ex |
| aterm | w1200ex firmware |
| aterm | w1200ex-ms |
| aterm | w1200ex-ms firmware |
| aterm | wg1200hp firmware |
| aterm | wg1200hp2 |
| aterm | wg1200hp2 firmware |
| aterm | wg1200hp3 |
| aterm | wg1200hp3 firmware |
| aterm | wg1200hs |
| aterm | wg1200hs firmware |
| aterm | wg1200hs2 |
| aterm | wg1200hs2 firmware |
| aterm | wg1800hp3 |
| aterm | wg1800hp3 firmware |
| aterm | wg1800hp4 |
| aterm | wg1800hp4 firmware |
| aterm | wg1900hp |
| aterm | wg1900hp firmware |
| aterm | wg1900hp2 |
| aterm | wg1900hp2 firmware |
| dlink | dir-501 |
| dlink | dir-501 firmware |
| dlink | dir-515 |
| dlink | dir-515 firmware |
| dlink | dir-600l |
| dlink | dir-600l firmware |
| dlink | dir-605l |
| dlink | dir-605l firmware |
| dlink | dir-615 |
| dlink | dir-615 firmware |
| dlink | dir-619l |
| dlink | dir-619l firmware |
| dlink | dir-809 |
| dlink | dir-809 firmware |
| dlink | dir-900l |
| dlink | dir-900l firmware |
| dlink | dir-905l |
| dlink | dir-905l firmware |
| realtek | realtek sdk |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Realtek SDK - Miniigd UPnP SOAP Command Execution (Metasploit) | 2015-06-01 |
References
- http://jvn.jp/en/jp/JVN47580234/index.html
- http://jvn.jp/en/jp/JVN67456944/index.html
- http://packetstormsecurity.com/files/132090/Realtek-SDK-Miniigd-UPnP-SOAP-Command-Execution.html
- http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10055
- http://www.securityfocus.com/bid/74330
- http://www.zerodayinitiative.com/advisories/ZDI-15-155/
- https://sensorstechforum.com/hinatabot-cve-2014-8361-ddos/
- https://web.archive.org/web/20150909230440/http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10055
- https://www.exploit-db.com/exploits/37169/
- http://jvn.jp/en/jp/JVN47580234/index.html
- http://jvn.jp/en/jp/JVN67456944/index.html
- http://packetstormsecurity.com/files/132090/Realtek-SDK-Miniigd-UPnP-SOAP-Command-Execution.html
- http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10055
- http://www.securityfocus.com/bid/74330
- http://www.zerodayinitiative.com/advisories/ZDI-15-155/
- https://sensorstechforum.com/hinatabot-cve-2014-8361-ddos/
- https://web.archive.org/web/20150909230440/http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10055
- https://www.exploit-db.com/exploits/37169/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-8361
→ the Explorer · watch your stack · NVD