CVE-2014-8361

Deferred
Published: 01 May 2015, 00:00
Last modified:21 Oct 2025, 23:56

Vulnerability Summary

Overall Risk (default)
critical
90/100
CVSS Score
10 HIGH
v2.0 (nvd)
EPSS Score
93.89% CRITICAL
94% probability -0.10%
KEV
Listed
CIRCL • CISA
2 listings
Ransomware
No reports
Public exploits
3 found
Dark Web
Not detected

Timeline

01 May 2015, 00:00
Published
Vulnerability first disclosed
18 Sept 2023, 00:00
Added to CISA KEV
Realtek SDK Improper Input Validation Vulnerability
09 Oct 2023, 00:00
CISA Remediation Due
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
21 Oct 2025, 23:56
Last Modified
Vulnerability information updated
12 Mar 2026, 00:00
Added to CIRCL KEV
Added to Known Exploited Vulnerabilities catalog

Description

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 10AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 93.89% Percentile: 100%

Affected Systems

  • atermw1200ex_firmware

    ≤ 1.3.1

  • atermw1200ex-ms_firmware

    ≤ 1.3.1

  • atermwg1200hp2_firmware

    ≤ 2.5.0

  • atermwg1200hp3_firmware

    ≤ 1.3.1

  • atermwg1200hs2_firmware

    ≤ 2.5.0

  • atermwg1800hp3_firmware

    ≤ 1.5.1

  • atermwg1800hp4_firmware

    ≤ 1.3.1

  • atermwg1900hp_firmware

    ≤ 2.5.1

  • atermwg1900hp2_firmware

    ≤ 1.3.1

  • dlinkdir-501_firmware

    ≤ 1.01b04

  • dlinkdir-515_firmware

    ≤ 1.01b04

  • dlinkdir-600l_firmware

    ≤ 1.15 | ≤ 2.056b06

  • dlinkdir-605l_firmware

    ≤ 1.14b06 | ≤ 2.07b02 | ≤ 3.03b07

  • dlinkdir-615_firmware

    10.01b02 | ≤ 6.06b03

  • dlinkdir-619l_firmware

    ≤ 1.15 | ≤ 2.07b02

  • dlinkdir-809_firmware

    ≤ 1.04b02

  • dlinkdir-900l_firmware

    < 1.15b01

  • dlinkdir-905l_firmware

    ≤ 2.05b01

  • realtekrealtek_sdk

    na

References (10)