PT-2014-2053 · Realtek · Realtek Sdk

Headlesszeke

+1

·

Publicado

2014-08-13

·

Atualizado

2025-12-01

·

CVE-2014-8361

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Realtek SDK (affected versions not specified)
Description The issue is related to the miniigd SOAP service in Realtek SDK, which allows remote attackers to execute arbitrary code via a crafted NewInternalClient request. This has been exploited in the wild through 2023. The vulnerability is associated with insufficient input validation, allowing an attacker to execute arbitrary code using specially formed requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-02015
CVE-2014-8361
ZDI-15-155

Produtos afetados

Realtek Sdk