CVE-2014-8361

CRITICALCVSS 9.8/10Actively ExploitedEPSS 99.98%

Last modified

CVE-2014-8361 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.. CISA has confirmed active exploitation in the wild. EPSS estimates a 99.98% chance of exploitation in the next 30 days.

Description

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
99.98%

100.0th percentile

Probability of exploitation in the next 30 days. Learn more

Exploitation Status

This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .

Affected Software

VendorProductVersions
DlinkDir-905l Firmware<= 2.05b01
DlinkDir-605l Firmware<= 1.14b06
DlinkDir-600l Firmware<= 1.15
DlinkDir-619l Firmware<= 1.15
DlinkDir-619l Firmware<= 2.07b02
DlinkDir-605l Firmware<= 2.07b02
DlinkDir-605l Firmware<= 3.03b07
DlinkDir-600l Firmware<= 2.056b06
DlinkDir-809 Firmware<= 1.04b02
DlinkDir-900l Firmware< 1.15b01
RealtekRealtek SdkAll versions
DlinkDir-501 Firmware<= 1.01b04
DlinkDir-515 Firmware<= 1.01b04
DlinkDir-615 Firmware10.01b02
DlinkDir-615 Firmware<= 6.06b03
AtermWg1900hp2 Firmware<= 1.3.1
AtermWg1900hp Firmware<= 2.5.1
AtermWg1800hp4 Firmware<= 1.3.1
AtermWg1800hp3 Firmware<= 1.5.1
AtermWg1200hs2 Firmware<= 2.5.0
AtermWg1200hp3 Firmware<= 1.3.1
AtermWg1200hp2 Firmware<= 2.5.0
AtermW1200ex Firmware<= 1.3.1
AtermW1200ex-Ms Firmware<= 1.3.1
AtermWg1200hs FirmwareAll versions
AtermWg1200hp FirmwareAll versions
AtermWf800hp FirmwareAll versions
AtermWf300hp2 FirmwareAll versions
AtermWr8165n FirmwareAll versions
AtermW500p FirmwareAll versions
AtermW300p FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2014-8361?
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
How severe is CVE-2014-8361?
CVE-2014-8361 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 99.98% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2014-8361?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-8361?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST