CVE-2014-8361

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/05/2015
Last modified:
22/10/2025

Description

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dlink:dir-905l_firmware:*:*:*:*:*:*:*:* 2.05b01 (including)
cpe:2.3:h:dlink:dir-905l:a1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-905l:b1:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-605l_firmware:*:*:*:*:*:*:*:* 1.14b06 (including)
cpe:2.3:h:dlink:dir-605l:a1:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-600l_firmware:*:*:*:*:*:*:*:* 1.15 (including)
cpe:2.3:h:dlink:dir-600l:a1:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-619l_firmware:*:*:*:*:*:*:*:* 1.15 (including)
cpe:2.3:h:dlink:dir-619l:a1:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-619l_firmware:*:*:*:*:*:*:*:* 2.07b02 (including)
cpe:2.3:h:dlink:dir-619l:b1:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-605l_firmware:*:*:*:*:*:*:*:* 2.07b02 (including)
cpe:2.3:h:dlink:dir-605l:b1:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-605l_firmware:*:*:*:*:*:*:*:* 3.03b07 (including)
cpe:2.3:h:dlink:dir-605l:c1:*:*:*:*:*:*:*