Vulnerability record · CVE-2014-8361 · published 1 May 2015
CVE-2014-8361: Realtek SDK miniigd SOAP service remote code execution
Dlink · Dir 905l Firmware
The miniigd SOAP service in the Realtek SDK fails to properly validate input in a NewInternalClient request, allowing remote code execution. The flaw affects firmware built on the SDK across D-Link and Aterm devices and has been exploited in the wild for years, making unpatched or end-of-life routers a persistent risk.
Description
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, confirmed in-the-wild exploitation, CISA KEV listing and near-maximum EPSS score make this an urgent, actively exploited remote code execution flaw.
What it is
The miniigd SOAP service in the Realtek SDK fails to properly validate input in a NewInternalClient request, allowing remote code execution. The flaw affects firmware built on the SDK across D-Link and Aterm devices and has been exploited in the wild for years, making unpatched or end-of-life routers a persistent risk.
Impact
An unauthenticated attacker can execute arbitrary code on the device, gaining full control of the router and its network position. This enables use in botnets, traffic interception and lateral movement into the internal network.
Attack surface
Reachable over the network through the UPnP/SOAP interface exposed by the miniigd service, typically on the LAN side but potentially wider if UPnP is exposed. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Listed in CISA KEV since 2023-09-18 with a required action deadline, and EPSS probability is 0.99975 (percentile 0.99978). Public exploit code exists (Exploit-DB 37169, Packet Storm, ZDI advisory) and the description states it was exploited in the wild through 2023.
What to do
- Apply vendor firmware updates for affected D-Link and Aterm devices; where no fix exists, discontinue use of the device as CISA advises.
- Disable UPnP and the miniigd SOAP service on devices that do not require it.
- Block or restrict access to UPnP/SOAP ports (commonly 1900/udp and the device's HTTP management port) at network boundaries and between segments.
- Isolate legacy routers on a separate network segment and restrict outbound traffic to limit botnet use.
- Inventory devices running Realtek SDK-based firmware and prioritize replacement of unsupported models.
Detection
- Monitor for SOAP requests containing NewInternalClient actions to the miniigd service, especially from unexpected or external sources.
- Alert on command injection patterns or shell metacharacters in UPnP/SOAP request bodies.
- Watch for outbound connections from router management interfaces to known DDoS or botnet command-and-control infrastructure.
- Review device logs for unexpected process execution or configuration changes on routers with UPnP enabled.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2014-8361 to the Known Exploited Vulnerabilities catalog on 18 September 2023 as "Realtek SDK Improper Input Validation Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 9 October 2023.
Affected products
26 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-8361 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2014-8361), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.