Skip to main content

CVE detail

CVE-2014-8361

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

CVSS 9.8 · CriticalBuzz score 69.5KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 69.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 14.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
27 evidence mentions in the snapshot
Diversity score
14.5
5 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
27 source links · newest first
  • Government agencies faced the highest volume of cyberattack campaigns in 2025, according to new findings from HPE Threat Labs, which tracked 1,186 active campaigns over the course of the year. The data covers activity observed between January 1 and December 31, 2025, and reflects a broad mix of sectors and attack types. Top sectors targeted by threat campaigns in 2025 (Source: HPE) AI and automation drive faster, more powerful cyberattacks Government agencies were targeted in … More →

    newswww.helpnetsecurity.comMar 18, 2026, 7:00 AM
  • An instance of the Corona Mirai botnet spreads via AVTECH CCTV zero-day and multiple previously known vulnerabilities. Akamai’s Security Intelligence and Response Team (SIRT) has detected a botnet campaign exploiting multiple previously known vulnerabilities and a newly discovered zero-day, tracked as CVE-2024-7029 (CVSS score: 8.7), in AVTECH CCTV cameras. The flaw is a command injection issue […]

    newssecurityaffairs.comAug 29, 2024, 12:50 PM
  • CISA says Owl Labs video conferencing device vulnerabilities that require the attacker to be in close range exploited in attacks

    newswww.securityweek.comSep 19, 2023, 10:00 AM
  • A new Golang-based DDoS botnet, tracked as HinataBot, targets routers and servers by exploiting known vulnerabilities. Akamai researchers spotted a new DDoS Golang-based botnet, dubbed HinataBot, which has been observed exploiting known flaws to compromise routers and servers. The experts reported that the HinataBot bot was seen being distributed since the beginning of 2023 and its operators are actively […]

    newssecurityaffairs.comMar 17, 2023, 3:41 PM
  • A new variant of the Mirai botnet, tracked as Moobot, was spotted scanning the Internet for vulnerable Tenda routers. Researchers from AT&T Alien Lab have spotted a new variant of the Mirai botnet, tracked asu Moobot, which was scanning the Internet for the CVE-2020-10987 remote code-execution (RCE) issue in Tenda routers. The botnet was linked […]

    newssecurityaffairs.comJun 16, 2021, 6:16 AM
  • 24th May – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 24th May, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has discovered multiple misconfiguration flaws in third party cloud services of Android applications, which have led to the exposure of sensitive personal data of more than 100 million Android […]

    vendorresearch.checkpoint.comMay 24, 2021, 5:06 PM
  • Mirai code re-use in GafgytSecurity Affairs

    Uptycs’ threat research team recently detected several variants of the Linux-based botnet malware family, “Gafgyt,”some of them re-used Mirai code. Uptycs’ threat research team recently detected several variants of the Linux-based botnet malware family, “Gafgyt”, via threat intelligence systems and our in-house osquery-based sandbox. Upon analysis, we identified several codes, techniques and implementations of Gafgyt, […]

    newssecurityaffairs.comApr 16, 2021, 8:56 AM
  • Netlab 360 experts discovered a new Mirai-based botnet dubbed ZHtrap that implements honeypot to find more victims. Researchers from Netlab 360 discovered a new Mirai-based botnet dubbed ZHtrap that implements honeypot to find more victims. ZHtrap propagates using four vulnerabilities, experts pointed out that the botnet mainly used to conduct DDoS attacks and scanning activities, […]

    newssecurityaffairs.comMar 17, 2021, 3:11 PM
  • The Mozi botnet accounted for 90% of the IoT network traffic observed between October 2019 and June 2020, IBM reported. Mozi is an IoT botnet that borrows the code from Mirai variants and the Gafgyt malware, it appeared on the threat landscape in late 2019. The Mozi botnet was spotted by security experts from 360 […]

    newssecurityaffairs.comSep 20, 2020, 2:06 PM
  • Mozi, a relatively new botnet, has fueled a significant increase in Internet of Things (IoT) botnet activity, IBM reported this week.

    newswww.securityweek.comSep 19, 2020, 11:53 AM
  • A new Mozi P2P botnet is actively targeting Netgear, D-Link, and Huawei routers by probing for weak Telnet passwords to compromise them. Security experts from 360 Netlab spotted a new Mozi P2P botnet that is actively targeting Netgear, D-Link, and Huawei routers by probing for weak Telnet passwords to compromise them. According to the researchers, […]

    newssecurityaffairs.comDec 25, 2019, 5:22 PM
  • Since October 2019, Unit 42 has been tracking a new ECHOBOT variant with 71 unique exploits, 13 of which haven’t been previously seen exploited in the wild prior to this version.

    vendorunit42.paloaltonetworks.comDec 13, 2019, 9:56 PM
  • New Gafgyt botnet targets Gaming ServersSecurity Affairs

    Palo Alto Networks discovered a new version of Gafgyt botnet composed of Home & Small Office Wireless routers used to attack gaming servers. Palo Alto Networks researchers discovered a new version of Gafgyt botnet targeting home & small office wireless routers, including Zyxel and Huawei routers, as well as devices with Realtek RTL81xx chipset. According […]

    newssecurityaffairs.comNov 3, 2019, 5:48 PM
  • Unit 42 researchers discovered an updated Gafgy variant that looks to infect home and small office WiFi routers of known commercial brands, like Zyxel, Huawei, and Realtek to attack gaming servers. More than 32,000 WiFi routers are potentially vulnerable to these exploits around the world.

    vendorunit42.paloaltonetworks.comOct 31, 2019, 1:00 PM
  • Our researchers have discovered a new Mirai variant that uses 8 new vulnerabilities and targets new IoT devices.

    vendorunit42.paloaltonetworks.comJun 7, 2019, 12:00 AM
  • Palo Alto Networks researchers discovered a new variant of the Mirai malware that is targeting more processor architectures than previous ones. Mirai botnet continues to be one of the most dangerous malware in the threat landscape, experts at Palo Alto Networks discovered a new variant that targets more processor architectures than before. Mirai malware first […]

    newssecurityaffairs.comApr 10, 2019, 8:53 AM
  • A recently discovered variant of the Mirai malware is targeting more processor architectures than before, which allows it to attack a wider range of Internet of Things (IoT) devices, Palo Alto Networks security researchers reveal.

    newswww.securityweek.comApr 9, 2019, 6:00 PM
  • Unit 42 discovers new samples of Mirai compiled for additional processors, Altera Nios II, OpenRISC, Tensilica Xtensa, and Xilinx MicroBlaze, potentially increasing the DDoS firepower of Mirai.

    vendorunit42.paloaltonetworks.comApr 8, 2019, 1:00 PM
  • Attackers looking to add IoT devices to their botnets are increasingly adding vulnerability exploitation to their attack arsenal, Netscout researchers warn. Instead on just relying on a list of common or default passwords or brute-forcing attacks, they are taking advantage of the fact that IoT devices are rarely updated and manufacturers take a lot of time to push out fixes for known flaws. Currently under exploitation In November 2018, the company detected many exploitation attempts … More →

    newswww.helpnetsecurity.comDec 14, 2018, 7:00 AM
  • The popular Anarchy botmaster builds a botnet of 18,000 Huawei routers in a few hours, and it is also planning to target vulnerable Realtek routers. NewSky Security first reported the born a new huge botnet, in just one day the botmaster compromised more than 18,000 Huawei routers. NewSky security researcher Ankit Anubhav announced that the […]

    newssecurityaffairs.comJul 20, 2018, 1:15 PM
  • Unit 42 documents the emergence of three malware campaigns built on publicly available source code for the Mirai and Gafgyt malware families that incorporate multiple known exploits affecting Internet of Things (IoT) device.

    vendorunit42.paloaltonetworks.comJul 20, 2018, 12:00 PM
  • Researchers at security firm Radware have spotted a new IoT botnet, dubbed JenX, the leverages the Grand Theft Auto videogame community to infect devices. Researchers at security firm Radware have spotted a new IoT botnet, dubbed JenX, that exploits vulnerabilities triggered by the Satori botnet and is leveraging the Grand Theft Auto videogame community to infect devices. […]

    newssecurityaffairs.comFeb 3, 2018, 11:59 AM
  • New Botnet Is Recruiting IoT DevicesSecurityWeek

    A new botnet is recruiting Internet of Things (IoT) devices by exploiting two vulnerabilities already popular among IoT botnets, Radware has discovered.

    newswww.securityweek.comFeb 2, 2018, 1:12 PM
  • IoT malware targeting zero-day vulnerabilitiesHelp Net Security

    Once it became evident that IoT devices can be relatively easily enslaved in botnets and that even their limited power can be used for a variety of nefarious purposes, it was open season for malicious actors. First, they targeted IoT devices with default or weak passwords, and manufacturers and users began changing them. Then they used known vulnerabilities, and IoT vendor increased their efforts to push out patches. Now, some botmasters are making a concentrated … More →

    newswww.helpnetsecurity.comJan 12, 2018, 8:41 PM
  • Unit 42 researchers outline the evolution of Satori, a malware family targeting zero-day vulnerabilities in IoT devices

    vendorunit42.paloaltonetworks.comJan 11, 2018, 11:00 AM
  • A flaw affecting Realtek SDK exposes SOHO routers to remote code execution attacks. List of vulnerable devices include D-Link and TRENDnet products. The security expert from DVLabs security researcher and content developer at HP Enterprise Security Ricky Lawshae discovered a (CVE-2014-8361) vulnerability that affects Realtek SDK used for RTL81xx chipsets. The exploitation of the vulnerability allows a […]

    newssecurityaffairs.comApr 30, 2015, 6:35 AM
  • Routers from D-Link, TRENDnet and likely other vendors are vulnerable to remote code execution attacks due to a flaw in a component of the Realtek software development kit (SDK).

    newswww.securityweek.comApr 29, 2015, 12:32 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence