← Vulnerability feed

Vulnerability record · CVE-2014-8361 · published 1 May 2015

CVE-2014-8361: Realtek SDK miniigd SOAP service remote code execution

Dlink · Dir 905l Firmware

The miniigd SOAP service in the Realtek SDK fails to properly validate input in a NewInternalClient request, allowing remote code execution. The flaw affects firmware built on the SDK across D-Link and Aterm devices and has been exploited in the wild for years, making unpatched or end-of-life routers a persistent risk.

9.8 CVSS 3.1 Critical CISA KEV since 18 Sep 2023 EPSS 100% · top 0.1%
9.8CVSS 3.1 base score, v2 10.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
26Affected product versions listed by NVD
19References
17 Jun 2026Last modified by NVD

Description

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, confirmed in-the-wild exploitation, CISA KEV listing and near-maximum EPSS score make this an urgent, actively exploited remote code execution flaw.

What it is

The miniigd SOAP service in the Realtek SDK fails to properly validate input in a NewInternalClient request, allowing remote code execution. The flaw affects firmware built on the SDK across D-Link and Aterm devices and has been exploited in the wild for years, making unpatched or end-of-life routers a persistent risk.

Impact

An unauthenticated attacker can execute arbitrary code on the device, gaining full control of the router and its network position. This enables use in botnets, traffic interception and lateral movement into the internal network.

Attack surface

Reachable over the network through the UPnP/SOAP interface exposed by the miniigd service, typically on the LAN side but potentially wider if UPnP is exposed. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Listed in CISA KEV since 2023-09-18 with a required action deadline, and EPSS probability is 0.99975 (percentile 0.99978). Public exploit code exists (Exploit-DB 37169, Packet Storm, ZDI advisory) and the description states it was exploited in the wild through 2023.

What to do

  • Apply vendor firmware updates for affected D-Link and Aterm devices; where no fix exists, discontinue use of the device as CISA advises.
  • Disable UPnP and the miniigd SOAP service on devices that do not require it.
  • Block or restrict access to UPnP/SOAP ports (commonly 1900/udp and the device's HTTP management port) at network boundaries and between segments.
  • Isolate legacy routers on a separate network segment and restrict outbound traffic to limit botnet use.
  • Inventory devices running Realtek SDK-based firmware and prioritize replacement of unsupported models.

Detection

  • Monitor for SOAP requests containing NewInternalClient actions to the miniigd service, especially from unexpected or external sources.
  • Alert on command injection patterns or shell metacharacters in UPnP/SOAP request bodies.
  • Watch for outbound connections from router management interfaces to known DDoS or botnet command-and-control infrastructure.
  • Review device logs for unexpected process execution or configuration changes on routers with UPnP enabled.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2014-8361 to the Known Exploited Vulnerabilities catalog on 18 September 2023 as "Realtek SDK Improper Input Validation Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 9 October 2023.

Affected products

26 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://jvn.jp/en/jp/JVN47580234/index.html Third Party Advisory
http://jvn.jp/en/jp/JVN67456944/index.html Third Party Advisory
http://packetstormsecurity.com/files/132090/Realtek-SDK-Miniigd-UPnP-SOAP-Command-Execution.html Third Party AdvisoryVDB Entry
http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10055 Vendor Advisory
http://www.securityfocus.com/bid/74330 Broken LinkThird Party AdvisoryVDB Entry
http://www.zerodayinitiative.com/advisories/ZDI-15-155/ Third Party AdvisoryVDB Entry
https://sensorstechforum.com/hinatabot-cve-2014-8361-ddos/ Third Party Advisory
https://web.archive.org/web/20150909230440/http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10055 Third Party Advisory
https://www.exploit-db.com/exploits/37169/ Third Party AdvisoryVDB Entry
http://jvn.jp/en/jp/JVN47580234/index.html Third Party Advisory
http://jvn.jp/en/jp/JVN67456944/index.html Third Party Advisory
http://packetstormsecurity.com/files/132090/Realtek-SDK-Miniigd-UPnP-SOAP-Command-Execution.html Third Party AdvisoryVDB Entry
http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10055 Vendor Advisory
http://www.securityfocus.com/bid/74330 Broken LinkThird Party AdvisoryVDB Entry
http://www.zerodayinitiative.com/advisories/ZDI-15-155/ Third Party AdvisoryVDB Entry
https://sensorstechforum.com/hinatabot-cve-2014-8361-ddos/ Third Party Advisory
https://web.archive.org/web/20150909230440/http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10055 Third Party Advisory
https://www.exploit-db.com/exploits/37169/ Third Party AdvisoryVDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-8361 US Government Resource

Track CVE-2014-8361 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2014-8361), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.