cbcvebase.
CVE-2014-8361
published 2015-05-01

CVE-2014-8361: The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild…

PriorityP197critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-10-09
Exploited in the wild
EPSS
99.98%
100.0th percentile
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

Affected

23 ranges
VendorProductVersion rangeFixed in
atermw1200ex-ms_firmware<= 1.3.1
atermw1200ex_firmware<= 1.3.1
atermwg1200hp2_firmware<= 2.5.0
atermwg1200hp3_firmware<= 1.3.1
atermwg1200hs2_firmware<= 2.5.0
atermwg1800hp3_firmware<= 1.5.1
atermwg1800hp4_firmware<= 1.3.1
atermwg1900hp2_firmware<= 1.3.1
atermwg1900hp_firmware<= 2.5.1
dlinkdir-501_firmware<= 1.01b04
dlinkdir-515_firmware<= 1.01b04
dlinkdir-600l_firmware<= 1.15
dlinkdir-600l_firmware<= 2.056b06
dlinkdir-605l_firmware<= 1.14b06
dlinkdir-605l_firmware<= 2.07b02
dlinkdir-605l_firmware<= 3.03b07
dlinkdir-615_firmware<= 6.06b03
dlinkdir-615_firmware
dlinkdir-619l_firmware<= 1.15
dlinkdir-619l_firmware<= 2.07b02
dlinkdir-809_firmware<= 1.04b02
dlinkdir-900l_firmware< 1.15b011.15b01
dlinkdir-905l_firmware<= 2.05b01

Detection & IOCsextracted from sources · hover to see the quote

ip185.244.25.168
url185.244.25.168/mips
url185.244.25.168/x86
url185.244.25.168/OwO/Tsunami.mips
url185.244.25.168/x86/mipsel
url185.244.25.221/bins/Yowai.mips
url185.244.25.221/bins/Yowai.mpsl
url185.244.25.221/bins/Yowai.x86
url185.244.25.221/Yowai.mips
hash402f7be58a8165c39e95b93334a706ec13fe076a2706d2c32d6360180bba0a74
hash76af2c3ff471916bc247e4c254c9b2affa51edb7e1a18825f36817e8c5921812
hash7bd284f4da09d3a95472a66e0867d778eeb59ed54738f6fb6e417e93c0b65685
hashf693442a7e30876b46fd636d9df25495261be5c1a4f7b13e0fe5afc1b908e774
hash2e66ee1b4414fe2fb17da4372c43a826dd7767c189120eafd427773769302e35
hashdd6e5607f137b6536097670a1211b4e20821ca136e2db26529948ff0a48555ff
port52869
ip178.62.227.13
url178.62.227.13/wrgjwrgjwrg246356356356/hmicroblazebe
url178.62.227.13/wrgjwrgjwrg246356356356/hmicroblazeel
url178.62.227.13/wrgjwrgjwrg246356356356/hnios2
url178.62.227.13/wrgjwrgjwrg246356356356/hopenrisc
url178.62.227.13/wrgjwrgjwrg246356356356/hxtensa
uaHito/2.0
path/picsdesc.xml
hash1e16db506c1b8376f8998907d75a4353c798530889224e5cfa8b21a36561a21f
hashcd9d823b0f1ce2cf7b89d3a705d1b28f7c7874dbf0409a9111220cf42e94bcb4
url176.32.33.123/vi/.bushido
url46.29.163.168/vi/.bushido
url46.17.43.229/vi/.bushido
url194.36.173.4/vi/.bushido
url194.36.173.4/exploit/.exploit
url89.46.223.70/airlink.sh
domainorksecpatrol.xyz
url89.46.223.70/dlink.sh
ip145.239.138.69
uaRift/2.0
path/tmp/666trapgod
  • CVE-2014-8361 exploits the miniigd UPnP SOAP service via HTTP POST to the WANIPConnection:1 service using the AddPortMapping action; the NewInternalClient parameter is used for OS command injection via backtick characters. Monitor for SOAP POST requests containing shell metacharacters (backticks) in the NewInternalClient field.
  • Scan for inbound TCP traffic on port 52869, which is the port used by the Realtek miniigd UPnP SOAP service targeted by CVE-2014-8361. Elevated scanning activity on this port is a strong indicator of exploitation attempts.
  • Yowai (Mirai variant) listens on port 6 for C2 commands. Detect outbound connections from IoT devices to port 6 as a potential indicator of Yowai infection.
  • Detect HTTP requests with User-Agent 'Hito/2.0' as an indicator of the Mirai variant hosted at 178.62.227.13 exploiting CVE-2014-8361 and other vulnerabilities.
  • The new Mirai variant (Unit 42, Feb 2019) uses a modified XOR obfuscation with 10 8-byte keys cumulatively XOR-ed, effectively equivalent to a byte-wise XOR with 0x5A. Use this as a config-table decryption signature when triaging samples.
  • Trend Micro IDS/IPS rule 1134286 covers CVE-2014-8361 (WEB Realtek SDK Miniigd UPnP SOAP Command Execution). Use this signature ID as a reference for detection tuning.
  • ·The Okiru/Satori CVE-2014-8361 exploit contains a typo in the requested URI (should be /picsdesc.xml), causing the SOAP request to fail with HTTP 404. The exploit was assessed as non-functional at the time of analysis, generating only background noise rather than successful compromises.
  • ·As of the Fortinet analysis (Dec 2017), at least 13,000 devices were potentially still vulnerable to CVE-2014-8361 based on Shodan results for port 52869, with Taiwan (33%), Ukraine (17%), and Japan (14%) as the top affected countries.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.