CVE Tools

Description

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

In plain language

AI Act now

If you use affected Realtek SDK–based router models (DIR-905L A1, DIR-605L A1, DIR-600L A1, DIR-619L A1, DIR-809L A1/A2, WRC-300F E B K, WRC-F300NF, WRC-300FEBK-S, WG1900HP2), a remote attacker can take over the device’s internet services, and this is already known to be exploited in the wild—so this is a serious “act now” issue.

Executive summary

CVE-2014-8361 is a remotely reachable arbitrary code execution flaw in the miniigd SOAP service (Realtek SDK) triggered by a crafted SOAP request (NewInternalClient); it is listed in CISA KEV with a 2023-10-09 remediation due date and has public exploits.

If affected, business impact
Full device takeoverMalware installation on network gatewayService disruption for office internetPotential data interception risk

What to do now

  1. Check whether your internet router matches one of these models: dir-905l a1, dir-605l a1, dir-600l a1, dir-619l a1, dir-809l a1, dir-809l a2, wrc-300febk, wrc-f300nf, wrc-300febk-s, WG1900HP2.
  2. For DIR-900L firmware specifically, update to firmware version 1.15b01 (this is the listed fixed version).
  3. If your device model is affected but there is no known fixed update for it, follow the vendor guidance: install updates only from trusted sources or discontinue use of the product.
  4. After updating, confirm the device firmware version changed and keep an eye on internet-facing behavior (unexpected reboots, new services, or unusual WAN traffic).
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 33 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Sep 18, 2023
Remediation due:Oct 9, 2023

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

4 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

References

and 15 more references View all →
1

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2014-8361 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows