CVE-2014-8361

CVE Published 2015-05-01
Related CWE(s) CWE-20: Improper Input Validation
Related Vendor(s) dlink, aterm, realtek
Related Product(s) dir-600l_firmware, dir-619l_firmware, w1200ex_firmware, dir-905l_firmware, dir-809_firmware, wg1200hp2_firmware, dir-605l_firmware, w1200ex-ms_firmware, dir-615_firmware, dir-501_firmware, wg1800hp3_firmware, realtek_sdk, wg1200hs_firmware, wg1800hp4_firmware, wf800hp_firmware, wg1200hp3_firmware, wr8165n_firmware, wg1200hp_firmware, dir-515_firmware, w300p_firmware, wg1900hp2_firmware, wg1200hs2_firmware, wf300hp2_firmware, wg1900hp_firmware, w500p_firmware
Exploitation Reported (CISA KEV) 2023-09-18
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References