LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2014-8361: Realtek SDK Improper Input Validation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 18, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Oct 9, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2014-8361 to its Known Exploited Vulnerabilities catalog on Sep 18, 2023, with a federal patch deadline of Oct 9, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafted NewInternalClient request.

CVE-2014-8361 is an improper input validation vulnerability in the Realtek SDK that affects the miniigd SOAP service. A remote attacker can send a crafted NewInternalClient request to execute malicious code on the device. This matters because Realtek SDK components are commonly embedded in networking and consumer devices; successful exploitation can give an attacker control of the affected system without authentication.

Public detail is limited to the CISA summary and CWE classification. Confirm all product-specific impact, fixed versions, and deployment guidance against the vendor advisory before acting.

How it works

The weakness is classified as CWE-20 (Improper Input Validation). The miniigd SOAP service fails to properly validate input supplied in a NewInternalClient request. An attacker who can reach the service over the network can craft a request that causes the service to execute attacker-controlled code.

No further exploit mechanics, payload formats, or privilege details are provided in the available facts. Treat any unauthenticated remote code execution path on an exposed management or UPnP-related SOAP interface as high risk until the vendor advisory confirms otherwise.

Am I affected? How to find it in your systems

Realtek SDK is typically found in embedded networking equipment, routers, gateways, and other devices that implement UPnP or miniigd-style SOAP services. Inventory efforts should focus on:

Detection of exploitation is limited by the lack of published indicators. Look for anomalous or unexpected NewInternalClient SOAP requests in device logs, sudden process crashes or restarts of the miniigd service, and unexplained outbound connections originating from the device after such requests. Enable and retain SOAP/UPnP access logs where the platform supports them. Confirm log formats and any vendor-supplied detection signatures against the advisory.

How to remediate

The primary remediation is to apply the vendor-supplied update or mitigation instructions for the Realtek SDK. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Do not rely on version numbers or patch identifiers not present in the vendor advisory; always validate the exact remediation package against that advisory.

If you can't patch immediately

Until a vendor fix can be applied, reduce exposure with compensating controls appropriate to this class of remote code-execution flaw on an embedded SOAP service:

These measures lower risk but do not eliminate it; schedule the vendor update or product replacement as soon as possible. If mitigations remain unavailable, plan to discontinue use of the affected product as directed by CISA.

If your data may have been exposed

Actively exploited remote code-execution vulnerabilities on network devices can lead to full device compromise and subsequent lateral movement or data theft. Known ransomware use of this CVE is not documented. If you believe devices running the vulnerable Realtek SDK were reachable by untrusted parties, treat them as potentially compromised: isolate them, preserve logs, and perform forensic review according to your incident-response plan. As a separate hygiene step, you can run a free exposure scan of your email addresses against known breach data sets to check whether credentials or personal information have appeared in prior public breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedRealtek · SDK
WeaknessCWE-20
Added to CISA KEVSep 18, 2023
Federal patch deadlineOct 9, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities