CVE-2014-8361 is a critical remote code execution vulnerability affecting the miniigd SOAP service in Realtek SDK, impacting products from vendors like D-Link and Aterm. With a CVSS score of 9.8, it allows unauthenticated attackers to execute arbitrary code over the network with low complexity, leading to complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as evidenced by its inclusion in the KEV catalog and numerous exploit modules available, including Metasploit. The high number of community discussions and media coverage underscore its significant and ongoing threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.05b01CPE matchmatch criteria | cpe:2.3:o:dlink:dir-905l_firmware:*:*:*:*:*:*:*:* | ||
<= 1.14b06CPE matchmatch criteria | cpe:2.3:o:dlink:dir-605l_firmware:*:*:*:*:*:*:*:* | ||
<= 1.15CPE matchmatch criteria | cpe:2.3:o:dlink:dir-600l_firmware:*:*:*:*:*:*:*:* | ||
<= 1.15CPE matchmatch criteria | cpe:2.3:o:dlink:dir-619l_firmware:*:*:*:*:*:*:*:* | ||
<= 2.07b02CPE matchmatch criteria | cpe:2.3:o:dlink:dir-619l_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.