CVE-2014-8361
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
Affected (31)
Products: Dlink: Dir 905l Firmware, Dir 605l Firmware, Dir 600l Firmware, Dir 619l Firmware, Dir 809 Firmware, Dir 900l Firmware, Dir 501 Firmware, Dir 515 Firmware, Dir 615 Firmware · Realtek: Realtek Sdk · Aterm: Wg1900hp2 Firmware, Wg1900hp Firmware, Wg1800hp4 Firmware, Wg1800hp3 Firmware, Wg1200hs2 Firmware, Wg1200hp3 Firmware, Wg1200hp2 Firmware, W1200ex Firmware, W1200ex Ms Firmware, Wg1200hs Firmware, Wg1200hp Firmware, Wf800hp Firmware, Wf300hp2 Firmware, Wr8165n Firmware, W500p Firmware, W300p Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.05b01 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dir 905l | Version a1 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.14b06 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dir 605l | Version a1 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.15 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dir 600l | Version a1 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.15 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dir 619l | Version a1 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.07b02 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dir 619l | Version b1 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.07b02 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dir 605l | Version b1 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.03b07 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dir 605l | Version c1 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.056b06 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dir 600l | Version b1 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.04b02 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dir 809 | Version a1 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.15b01 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dir 900l | Version a1 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.01b04 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dir 501 | Version a1 |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.01b04 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dir 515 | Version a1 |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.01b02 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dir 615 | Version j1 |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 6.06b03 |
| Running on/with | Platform Versions |
|---|---|
Dlink Dir 615 | Version fx |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.3.1 |
| Running on/with | Platform Versions |
|---|---|
Aterm Wg1900hp2 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.5.1 |
| Running on/with | Platform Versions |
|---|---|
Aterm Wg1900hp | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.3.1 |
| Running on/with | Platform Versions |
|---|---|
Aterm Wg1800hp4 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.5.1 |
| Running on/with | Platform Versions |
|---|---|
Aterm Wg1800hp3 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.5.0 |
| Running on/with | Platform Versions |
|---|---|
Aterm Wg1200hs2 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.3.1 |
| Running on/with | Platform Versions |
|---|---|
Aterm Wg1200hp3 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.5.0 |
| Running on/with | Platform Versions |
|---|---|
Aterm Wg1200hp2 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.3.1 |
| Running on/with | Platform Versions |
|---|---|
Aterm W1200ex | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.3.1 |
| Running on/with | Platform Versions |
|---|---|
Aterm W1200ex Ms | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Aterm Wg1200hs | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Aterm Wg1200hp | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Aterm Wf800hp | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Aterm Wf300hp2 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Aterm Wr8165n | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Aterm W500p | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Aterm W300p | All versions |
References (19)
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.