10

CVE-2014-8361

Warnung

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DlinkDir-905l Firmware Version <= 2.05b01
   DlinkDir-905l Versiona1
   DlinkDir-905l Versionb1
DlinkDir-605l Firmware Version <= 1.14b06
   DlinkDir-605l Versiona1
DlinkDir-600l Firmware Version <= 1.15
   DlinkDir-600l Versiona1
DlinkDir-619l Firmware Version <= 1.15
   DlinkDir-619l Versiona1
DlinkDir-619l Firmware Version <= 2.07b02
   DlinkDir-619l Versionb1
DlinkDir-605l Firmware Version <= 2.07b02
   DlinkDir-605l Versionb1
DlinkDir-605l Firmware Version <= 3.03b07
   DlinkDir-605l Versionc1
DlinkDir-600l Firmware Version <= 2.056b06
   DlinkDir-600l Versionb1
DlinkDir-809 Firmware Version <= 1.04b02
   DlinkDir-809 Versiona1
   DlinkDir-809 Versiona2
DlinkDir-900l Firmware Version < 1.15b01
   DlinkDir-900l Versiona1
RealtekRealtek Sdk Version-
DlinkDir-501 Firmware Version <= 1.01b04
   DlinkDir-501 Versiona1
DlinkDir-515 Firmware Version <= 1.01b04
   DlinkDir-515 Versiona1
DlinkDir-615 Firmware Version10.01b02
   DlinkDir-615 Versionj1
DlinkDir-615 Firmware Version <= 6.06b03
   DlinkDir-615 Versionfx
AtermWg1900hp2 Firmware Version <= 1.3.1
   AtermWg1900hp2 Version-
AtermWg1900hp Firmware Version <= 2.5.1
   AtermWg1900hp Version-
AtermWg1800hp4 Firmware Version <= 1.3.1
   AtermWg1800hp4 Version-
AtermWg1800hp3 Firmware Version <= 1.5.1
   AtermWg1800hp3 Version-
AtermWg1200hs2 Firmware Version <= 2.5.0
   AtermWg1200hs2 Version-
AtermWg1200hp3 Firmware Version <= 1.3.1
   AtermWg1200hp3 Version-
AtermWg1200hp2 Firmware Version <= 2.5.0
   AtermWg1200hp2 Version-
AtermW1200ex Firmware Version <= 1.3.1
   AtermW1200ex Version-
AtermW1200ex-ms Firmware Version <= 1.3.1
   AtermW1200ex-ms Version-
AtermWg1200hs Firmware
   AtermWg1200hs Version-
AtermWg1200hp Firmware
   AtermWg1200hp Version-
AtermWf800hp Firmware
   AtermWf800hp Version-
AtermWf300hp2 Firmware
   AtermWf300hp2 Version-
AtermWr8165n Firmware
   AtermWr8165n Version-
AtermW500p Firmware
   AtermW500p Version-
AtermW300p Firmware
   AtermW300p Version-

18.09.2023: CISA Known Exploited Vulnerabilities (KEV) Catalog

Realtek SDK Improper Input Validation Vulnerability

Schwachstelle

Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafted NewInternalClient request.

Beschreibung

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 94.03% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H