cbcvebase.
CVE-2014-8361
published 2015-05-01

CVE-2014-8361: The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-10-09
Exploited in the wild
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

Affected

23 ranges
VendorProductVersion rangeFixed in
atermw1200ex-ms_firmware<= 1.3.1
atermw1200ex_firmware<= 1.3.1
atermwg1200hp2_firmware<= 2.5.0
atermwg1200hp3_firmware<= 1.3.1
atermwg1200hs2_firmware<= 2.5.0
atermwg1800hp3_firmware<= 1.5.1
atermwg1800hp4_firmware<= 1.3.1
atermwg1900hp2_firmware<= 1.3.1
atermwg1900hp_firmware<= 2.5.1
dlinkdir-501_firmware<= 1.01b04
dlinkdir-515_firmware<= 1.01b04
dlinkdir-600l_firmware<= 1.15
dlinkdir-600l_firmware<= 2.056b06
dlinkdir-605l_firmware<= 1.14b06
dlinkdir-605l_firmware<= 2.07b02
dlinkdir-605l_firmware<= 3.03b07
dlinkdir-615_firmware<= 6.06b03
dlinkdir-615_firmware
dlinkdir-619l_firmware<= 1.15
dlinkdir-619l_firmware<= 2.07b02
dlinkdir-809_firmware<= 1.04b02
dlinkdir-900l_firmware< 1.15b011.15b01
dlinkdir-905l_firmware<= 2.05b01

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL