CVE-2014-8361

CRITICAL KEV

Realtek SDK - Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2014-8361 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added September 18, 2023. EIP tracks 3 public exploits from researchers including Metasploit, Ricky, Lawshae, including a Metasploit module exploits/linux/http/realtek_miniigd_upnp_exec_noauth.

AI-analyzed exploit summary This Metasploit module exploits a blind OS command injection vulnerability in the Realtek SDK's miniigd UPnP SOAP interface. It targets devices using the vulnerable SDK, such as the Trendnet TEW-731BR router, by injecting commands into the SOAP request parameters.

Description

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/37169

This Metasploit module exploits a blind OS command injection vulnerability in the Realtek SDK's miniigd UPnP SOAP interface. It targets devices using the vulnerable SDK, such as the Trendnet TEW-731BR router, by injecting commands into the SOAP request parameters.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Realtek SDK miniigd daemon (UPnP SOAP interface)
No auth needed
Prerequisites: Network access to the vulnerable device's UPnP SOAP interface (port 52869 by default) · Device running Realtek SDK with vulnerable miniigd daemon
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Ricky, Lawshae · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/realtek_miniigd_upnp_exec_noauth.rb

This Metasploit module exploits a blind OS command injection vulnerability in the Realtek SDK's miniigd UPnP SOAP interface. It targets devices using the vulnerable SDK, allowing remote command execution without authentication.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Realtek SDK miniigd daemon (UPnP SOAP interface)
No auth needed
Prerequisites: Network access to the vulnerable device's UPnP SOAP interface (port 52869) · Device running Realtek SDK with vulnerable miniigd daemon
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/dlink_upnp_exec_noauth.rb

This Metasploit module exploits a blind OS command injection vulnerability in D-Link routers via the UPnP SOAP interface. It targets the 'NewInternalClient' field in the 'AddPortMapping' SOAP action to execute arbitrary commands without authentication.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: D-Link DIR-865, DIR-645 (and potentially other models)
No auth needed
Prerequisites: Network access to the UPnP SOAP interface (port 49152 by default) · Vulnerable D-Link device
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.9402
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2023-09-18
VulnCheck KEV 2015-05-01
InTheWild.io 2022-12-22
ENISA EUVD EUVD-2014-8198
Status published
Products (27)
aterm/w1200ex-ms_firmware < 1.3.1
aterm/w1200ex_firmware < 1.3.1
aterm/w300p_firmware
aterm/w500p_firmware
aterm/wf300hp2_firmware
aterm/wf800hp_firmware
aterm/wg1200hp2_firmware < 2.5.0
aterm/wg1200hp3_firmware < 1.3.1
aterm/wg1200hp_firmware
aterm/wg1200hs2_firmware < 2.5.0
... and 17 more
Published May 01, 2015
KEV Added Sep 18, 2023
Tracked Since Feb 18, 2026