PT-2014-2053 · Realtek · Realtek Sdk

Headlesszeke

+1

·

Published

2014-08-13

·

Updated

2025-12-01

·

CVE-2014-8361

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Realtek SDK (affected versions not specified)
Description The issue is related to the miniigd SOAP service in Realtek SDK, which allows remote attackers to execute arbitrary code via a crafted NewInternalClient request. This has been exploited in the wild through 2023. The vulnerability is associated with insufficient input validation, allowing an attacker to execute arbitrary code using specially formed requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

BDU:2023-02015
CVE-2014-8361
ZDI-15-155

Affected Products

Realtek Sdk