A remote code execution flaw in the Realtek SDK miniigd SOAP service allows attackers to run arbitrary code by sending a crafted NewInternalClient request. The issue, tracked as CVE-2014-8361, was documented by MITRE and linked to an authentication bypass and RCE condition affecting devices built on the vulnerable SDK, including products covered by D-Link advisory SAP10055.
The vulnerability was originally disclosed through multiple security advisories and exploit publications, including references from the Zero Day Initiative, Packet Storm, Exploit-DB, SecurityFocus, and JVN. MITRE’s record notes that the flaw continued to be exploited in the wild through 2023, underscoring the long tail of risk for internet-exposed embedded devices that still rely on the affected Realtek software components.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
The CVE-2014-8361 record was updated, and the entry states the vulnerability had been exploited in the wild through 2023.
MITRE published the CVE-2014-8361 record for a remote code execution vulnerability in the Realtek SDK miniigd SOAP service that can be triggered with a crafted NewInternalClient request.
D-Link published security advisory SAP10055 covering an authentication bypass and remote code execution issue in the Realtek SDK miniigd component.
A command injection vulnerability affecting multiple D-Link routers' UPnP SOAP interface was disclosed, allowing shell commands to be injected via the NewInternalClient field of the AddPortMapping action. The issue was reported as affecting tested DIR-300, DIR-600, DIR-645, DIR-845, and DIR-865 devices, with additional models potentially vulnerable.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcesecurityadvisories.dlink.com
Open sourceexploit-db.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.