CVE-2014-8361
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Realtek SDK Improper Input Validation Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-24/7/2026
מוצרים מושפעים
dlink: dir-905l firmware; dlink: dir-905l; dlink: dir-605l firmware; dlink: dir-605l; dlink: dir-600l firmware; dlink: dir-600l; dlink: dir-619l firmware; dlink: dir-619l; dlink: dir-809 firmware; dlink: dir-809; dlink: dir-900l firmware; dlink: dir-900l; realtek: realtek sdk; dlink: dir-501 firmware; dlink: dir-501
קישורים
- http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10055 Vendor Advisory
- http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10055 Vendor Advisory
- http://jvn.jp/en/jp/JVN47580234/index.html Third Party Advisory
- http://jvn.jp/en/jp/JVN67456944/index.html Third Party Advisory
- http://packetstormsecurity.com/files/132090/Realtek-SDK-Miniigd-UPnP-SOAP-Comm… Third Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/74330 Broken LinkThird Party AdvisoryVDB Entry
- http://www.zerodayinitiative.com/advisories/ZDI-15-155/ Third Party AdvisoryVDB Entry
- https://sensorstechforum.com/hinatabot-cve-2014-8361-ddos/ Third Party Advisory
- https://web.archive.org/web/20150909230440/http://securityadvisories.dlink.com… Third Party Advisory
- https://www.exploit-db.com/exploits/37169/ Third Party AdvisoryVDB Entry