CVE-2014-8361

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
dlinkdir-905l_firmware
𝑥
≤ 2.05b01
dlinkdir-605l_firmware
𝑥
≤ 1.14b06
dlinkdir-600l_firmware
𝑥
≤ 1.15
dlinkdir-619l_firmware
𝑥
≤ 1.15
dlinkdir-619l_firmware
𝑥
≤ 2.07b02
dlinkdir-605l_firmware
𝑥
≤ 2.07b02
dlinkdir-605l_firmware
𝑥
≤ 3.03b07
dlinkdir-600l_firmware
𝑥
≤ 2.056b06
dlinkdir-809_firmware
𝑥
≤ 1.04b02
dlinkdir-900l_firmware
𝑥
< 1.15b01
realtekrealtek_sdk
-
dlinkdir-501_firmware
𝑥
≤ 1.01b04
dlinkdir-515_firmware
𝑥
≤ 1.01b04
dlinkdir-615_firmware
10.01b02:b02
dlinkdir-615_firmware
𝑥
≤ 6.06b03
atermwg1900hp2_firmware
𝑥
≤ 1.3.1
atermwg1900hp_firmware
𝑥
≤ 2.5.1
atermwg1800hp4_firmware
𝑥
≤ 1.3.1
atermwg1800hp3_firmware
𝑥
≤ 1.5.1
atermwg1200hs2_firmware
𝑥
≤ 2.5.0
atermwg1200hp3_firmware
𝑥
≤ 1.3.1
atermwg1200hp2_firmware
𝑥
≤ 2.5.0
atermw1200ex_firmware
𝑥
≤ 1.3.1
atermw1200ex-ms_firmware
𝑥
≤ 1.3.1
atermwg1200hs_firmware
*
atermwg1200hp_firmware
*
atermwf800hp_firmware
*
atermwf300hp2_firmware
*
atermwr8165n_firmware
*
atermw500p_firmware
*
atermw300p_firmware
*
𝑥
= Vulnerable software versions