Junglewise Threat Intelligence

CVE-2014-8361: Realtek SDK Improper Input Validation Vulnerability

CVE-2014-8361 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-09-18

Technologies: Realtek SDK. Vendors: D-Link, Realtek.

Executive brief

The miniigd SOAP service in the Realtek SDK contains an improper input validation vulnerability. Remote attackers can execute arbitrary code by sending a specially crafted NewInternalClient request. This vulnerability has been observed in active exploitation, including use by botnets.

Affected products

  • Realtek SDK
  • D-Link DIR-615 Firmware up to 6.06b03
  • D-Link DIR-600L Firmware up to 1.15 (A1), up to 2.056b06 (B1)
  • D-Link DIR-605L Firmware up to 1.14b06 (A1), up to 2.07b02 (B1), up to 3.03b07 (C1)
  • D-Link DIR-619L Firmware up to 1.15 (A1), up to 2.07b02 (B1)
  • D-Link DIR-809 Firmware up to 1.04b02 (A1/A2)
  • D-Link DIR-900L Firmware up to (excluding) 1.15b01 (A1)
  • D-Link DIR-905L Firmware up to 2.05b01 (A1/B1)

Timeline

  • 2015-04-24: disclosed: Initial vulnerability disclosure date (based on BID 74330)
  • 2023-09-18: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-09-18: advisory: NVD publication date
  • 2023-10-09: other: CISA remediation due date
  • 2023-09-18: exploited: Confirmed exploited in the wild through 2023