CVE-2014-8361: Realtek SDK Improper Input Validation Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2023-09-18. EPSS: 100% chance of exploitation in the next 30 days.

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

Affected products

  • Aterm w1200ex-Ms Firmware: up to and including 1.3.1
  • Aterm w1200ex Firmware: up to and including 1.3.1
  • Aterm w300p Firmware: any version
  • Aterm w500p Firmware: any version
  • Aterm WF300HP2 Firmware: any version
  • Aterm WF800HP Firmware: any version
  • Aterm WG1200HP2 Firmware: up to and including 2.5.0
  • Aterm WG1200HP3 Firmware: up to and including 1.3.1
  • Aterm WG1200HP Firmware: any version
  • Aterm WG1200HS2 Firmware: up to and including 2.5.0
  • Aterm WG1200HS Firmware: any version
  • Aterm WG1800HP3 Firmware: up to and including 1.5.1
  • Aterm WG1800HP4 Firmware: up to and including 1.3.1
  • Aterm WG1900HP2 Firmware: up to and including 1.3.1
  • Aterm WG1900HP Firmware: up to and including 2.5.1
  • Aterm WR8165N Firmware: any version
  • D-Link Dir-501 Firmware: up to and including 1.01b04
  • D-Link Dir-515 Firmware: up to and including 1.01b04
  • D-Link Dir-600l Firmware: up to and including 1.15; up to and including 2.056b06
  • D-Link Dir-605l Firmware: up to and including 1.14b06; up to and including 2.07b02; up to and including 3.03b07
  • D-Link Dir-615 Firmware: version 10.01b02 only; up to and including 6.06b03
  • D-Link Dir-619l Firmware: up to and including 1.15; up to and including 2.07b02
  • D-Link Dir-809 Firmware: up to and including 1.04b02
  • D-Link Dir-900l Firmware: before 1.15b01 (fixed in 1.15b01)
  • D-Link Dir-905l Firmware: up to and including 2.05b01
  • and 1 more

Published 2015-05-01. Last modified 2026-06-17.