CVE Feed

    Dashboard / CVE / CVE-2014-8361

    CVE-2014-8361

    The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

    Published:May 1, 2015
    Last Modified:Apr 22, 2026
    EPS:May 1, 2015
    EPSS Score:0.93992
    CVSS Score:9.8

    CISA Notification

    Description

    The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

    Required Action:

    Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Notes:

    No extra notes provided.

    Due Date
    Oct 9, 2023
    1068 days ago
    Alert Date
    Sep 18, 2023
    1089 days ago

    Affected Products

    Vendor
    Aterm
    Product
    W1200ex
    Vendor
    Aterm
    Product
    W1200ex-ms
    Vendor
    Aterm
    Product
    W1200ex-ms Firmware
    Vendor
    Aterm
    Product
    W1200ex Firmware
    Vendor
    Aterm
    Product
    W300p
    Vendor
    Aterm
    Product
    W300p Firmware
    Vendor
    Aterm
    Product
    W500p
    Vendor
    Aterm
    Product
    W500p Firmware
    Vendor
    Aterm
    Product
    Wf300hp2
    Vendor
    Aterm
    Product
    Wf300hp2 Firmware
    Vendor
    Aterm
    Product
    Wf800hp
    Vendor
    Aterm
    Product
    Wf800hp Firmware
    Vendor
    Aterm
    Product
    Wg1200hp
    Vendor
    Aterm
    Product
    Wg1200hp2
    Vendor
    Aterm
    Product
    Wg1200hp2 Firmware
    Vendor
    Aterm
    Product
    Wg1200hp3
    Vendor
    Aterm
    Product
    Wg1200hp3 Firmware
    Vendor
    Aterm
    Product
    Wg1200hp Firmware
    Vendor
    Aterm
    Product
    Wg1200hs
    Vendor
    Aterm
    Product
    Wg1200hs2
    Vendor
    Aterm
    Product
    Wg1200hs2 Firmware
    Vendor
    Aterm
    Product
    Wg1200hs Firmware
    Vendor
    Aterm
    Product
    Wg1800hp3
    Vendor
    Aterm
    Product
    Wg1800hp3 Firmware
    Vendor
    Aterm
    Product
    Wg1800hp4
    Vendor
    Aterm
    Product
    Wg1800hp4 Firmware
    Vendor
    Aterm
    Product
    Wg1900hp
    Vendor
    Aterm
    Product
    Wg1900hp2
    Vendor
    Aterm
    Product
    Wg1900hp2 Firmware
    Vendor
    Aterm
    Product
    Wg1900hp Firmware
    Vendor
    Aterm
    Product
    Wr8165n
    Vendor
    Aterm
    Product
    Wr8165n Firmware
    Vendor
    Dlink
    Product
    Dir-501
    Vendor
    Dlink
    Product
    Dir-501 Firmware
    Vendor
    Dlink
    Product
    Dir-515
    Vendor
    Dlink
    Product
    Dir-515 Firmware
    Vendor
    Dlink
    Product
    Dir-600l
    Vendor
    Dlink
    Product
    Dir-600l Firmware
    Vendor
    Dlink
    Product
    Dir-605l
    Vendor
    Dlink
    Product
    Dir-605l Firmware
    Vendor
    Dlink
    Product
    Dir-615
    Vendor
    Dlink
    Product
    Dir-615 Firmware
    Vendor
    Dlink
    Product
    Dir-619l
    Vendor
    Dlink
    Product
    Dir-619l Firmware
    Vendor
    Dlink
    Product
    Dir-809
    Vendor
    Dlink
    Product
    Dir-809 Firmware
    Vendor
    Dlink
    Product
    Dir-900l
    Vendor
    Dlink
    Product
    Dir-900l Firmware
    Vendor
    Dlink
    Product
    Dir-905l
    Vendor
    Dlink
    Product
    Dir-905l Firmware
    Vendor
    Realtek
    Product
    Realtek Sdk

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High