CVE-2014-8361: Realtek SDK Improper Input Validation Vulnerability
Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafted NewInternalClient request.
Other sources
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2014-8361?
CVE-2014-8361 is a critical vulnerability that allows remote code execution due to improper input validation in the Realtek SDK.
How do I fix CVE-2014-8361?
To fix CVE-2014-8361, update the firmware of affected devices to the latest version provided by the vendor.
Which devices are affected by CVE-2014-8361?
Devices using the Realtek SDK, including various D-Link routers, are affected by CVE-2014-8361.
What types of attacks can exploit CVE-2014-8361?
CVE-2014-8361 can be exploited by remote attackers to execute arbitrary code through a crafted SOAP request.
Is there a workaround for CVE-2014-8361 if I cannot update?
A temporary workaround for CVE-2014-8361 may include disabling the miniigd SOAP service until a patch is applied.