Описание
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request.
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2014-8361
- https://sensorstechforum.com/hinatabot-cve-2014-8361-ddos
- https://web.archive.org/web/20150909230440/http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10055
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-8361
- https://www.exploit-db.com/exploits/37169
- http://jvn.jp/en/jp/JVN47580234/index.html
- http://jvn.jp/en/jp/JVN67456944/index.html
- http://packetstormsecurity.com/files/132090/Realtek-SDK-Miniigd-UPnP-SOAP-Command-Execution.html
- http://securityadvisories.dlink.com/security/publication.aspx?name=SAP10055
- http://www.securityfocus.com/bid/74330
- http://www.zerodayinitiative.com/advisories/ZDI-15-155
Связанные уязвимости
CVSS3: 9.8
nvd
почти 11 лет назад
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
CVSS3: 8.8
fstec
больше 11 лет назад
Уязвимость службы miniigd SOAP гигабитных Ethernet-чипов Realtek RTL81xx, позволяющая нарушителю выполнить произвольный код