CVE detail
CVE-2014-8361
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 14.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
27 source links · newest first
- Cybercriminals scale up, government sector hit hardestHelp Net Security
Government agencies faced the highest volume of cyberattack campaigns in 2025, according to new findings from HPE Threat Labs, which tracked 1,186 active campaigns over the course of the year. The data covers activity observed between January 1 and December 31, 2025, and reflects a broad mix of sectors and attack types. Top sectors targeted by threat campaigns in 2025 (Source: HPE) AI and automation drive faster, more powerful cyberattacks Government agencies were targeted in … More →
newswww.helpnetsecurity.comMar 18, 2026, 7:00 AM - Corona Mirai botnet spreads via AVTECH CCTV zero-daySecurity Affairs
An instance of the Corona Mirai botnet spreads via AVTECH CCTV zero-day and multiple previously known vulnerabilities. Akamai’s Security Intelligence and Response Team (SIRT) has detected a botnet campaign exploiting multiple previously known vulnerabilities and a newly discovered zero-day, tracked as CVE-2024-7029 (CVSS score: 8.7), in AVTECH CCTV cameras. The flaw is a command injection issue […]
newssecurityaffairs.comAug 29, 2024, 12:50 PM CISA says Owl Labs video conferencing device vulnerabilities that require the attacker to be in close range exploited in attacks
newswww.securityweek.comSep 19, 2023, 10:00 AM- HinataBot, a new Go-Based DDoS botnet in the threat landscapeSecurity Affairs
A new Golang-based DDoS botnet, tracked as HinataBot, targets routers and servers by exploiting known vulnerabilities. Akamai researchers spotted a new DDoS Golang-based botnet, dubbed HinataBot, which has been observed exploiting known flaws to compromise routers and servers. The experts reported that the HinataBot bot was seen being distributed since the beginning of 2023 and its operators are actively […]
newssecurityaffairs.comMar 17, 2023, 3:41 PM A new variant of the Mirai botnet, tracked as Moobot, was spotted scanning the Internet for vulnerable Tenda routers. Researchers from AT&T Alien Lab have spotted a new variant of the Mirai botnet, tracked asu Moobot, which was scanning the Internet for the CVE-2020-10987 remote code-execution (RCE) issue in Tenda routers. The botnet was linked […]
newssecurityaffairs.comJun 16, 2021, 6:16 AM- 24th May – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 24th May, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has discovered multiple misconfiguration flaws in third party cloud services of Android applications, which have led to the exposure of sensitive personal data of more than 100 million Android […]
vendorresearch.checkpoint.comMay 24, 2021, 5:06 PM - Mirai code re-use in GafgytSecurity Affairs
Uptycs’ threat research team recently detected several variants of the Linux-based botnet malware family, “Gafgyt,”some of them re-used Mirai code. Uptycs’ threat research team recently detected several variants of the Linux-based botnet malware family, “Gafgyt”, via threat intelligence systems and our in-house osquery-based sandbox. Upon analysis, we identified several codes, techniques and implementations of Gafgyt, […]
newssecurityaffairs.comApr 16, 2021, 8:56 AM - New ZHtrap botnet uses honeypot to find more victimsSecurity Affairs
Netlab 360 experts discovered a new Mirai-based botnet dubbed ZHtrap that implements honeypot to find more victims. Researchers from Netlab 360 discovered a new Mirai-based botnet dubbed ZHtrap that implements honeypot to find more victims. ZHtrap propagates using four vulnerabilities, experts pointed out that the botnet mainly used to conduct DDoS attacks and scanning activities, […]
newssecurityaffairs.comMar 17, 2021, 3:11 PM - Mozi Botnet is responsible for most of the IoT TrafficSecurity Affairs
The Mozi botnet accounted for 90% of the IoT network traffic observed between October 2019 and June 2020, IBM reported. Mozi is an IoT botnet that borrows the code from Mirai variants and the Gafgyt malware, it appeared on the threat landscape in late 2019. The Mozi botnet was spotted by security experts from 360 […]
newssecurityaffairs.comSep 20, 2020, 2:06 PM Mozi, a relatively new botnet, has fueled a significant increase in Internet of Things (IoT) botnet activity, IBM reported this week.
newswww.securityweek.comSep 19, 2020, 11:53 AM- New Mozi P2P Botnet targets Netgear, D-Link, Huawei routersSecurity Affairs
A new Mozi P2P botnet is actively targeting Netgear, D-Link, and Huawei routers by probing for weak Telnet passwords to compromise them. Security experts from 360 Netlab spotted a new Mozi P2P botnet that is actively targeting Netgear, D-Link, and Huawei routers by probing for weak Telnet passwords to compromise them. According to the researchers, […]
newssecurityaffairs.comDec 25, 2019, 5:22 PM Since October 2019, Unit 42 has been tracking a new ECHOBOT variant with 71 unique exploits, 13 of which haven’t been previously seen exploited in the wild prior to this version.
vendorunit42.paloaltonetworks.comDec 13, 2019, 9:56 PM- New Gafgyt botnet targets Gaming ServersSecurity Affairs
Palo Alto Networks discovered a new version of Gafgyt botnet composed of Home & Small Office Wireless routers used to attack gaming servers. Palo Alto Networks researchers discovered a new version of Gafgyt botnet targeting home & small office wireless routers, including Zyxel and Huawei routers, as well as devices with Realtek RTL81xx chipset. According […]
newssecurityaffairs.comNov 3, 2019, 5:48 PM Unit 42 researchers discovered an updated Gafgy variant that looks to infect home and small office WiFi routers of known commercial brands, like Zyxel, Huawei, and Realtek to attack gaming servers. More than 32,000 WiFi routers are potentially vulnerable to these exploits around the world.
vendorunit42.paloaltonetworks.comOct 31, 2019, 1:00 PMOur researchers have discovered a new Mirai variant that uses 8 new vulnerabilities and targets new IoT devices.
vendorunit42.paloaltonetworks.comJun 7, 2019, 12:00 AM- Experts spotted a new Mirai variant that targets new processorsSecurity Affairs
Palo Alto Networks researchers discovered a new variant of the Mirai malware that is targeting more processor architectures than previous ones. Mirai botnet continues to be one of the most dangerous malware in the threat landscape, experts at Palo Alto Networks discovered a new variant that targets more processor architectures than before. Mirai malware first […]
newssecurityaffairs.comApr 10, 2019, 8:53 AM A recently discovered variant of the Mirai malware is targeting more processor architectures than before, which allows it to attack a wider range of Internet of Things (IoT) devices, Palo Alto Networks security researchers reveal.
newswww.securityweek.comApr 9, 2019, 6:00 PMUnit 42 discovers new samples of Mirai compiled for additional processors, Altera Nios II, OpenRISC, Tensilica Xtensa, and Xilinx MicroBlaze, potentially increasing the DDoS firepower of Mirai.
vendorunit42.paloaltonetworks.comApr 8, 2019, 1:00 PMAttackers looking to add IoT devices to their botnets are increasingly adding vulnerability exploitation to their attack arsenal, Netscout researchers warn. Instead on just relying on a list of common or default passwords or brute-forcing attacks, they are taking advantage of the fact that IoT devices are rarely updated and manufacturers take a lot of time to push out fixes for known flaws. Currently under exploitation In November 2018, the company detected many exploitation attempts … More →
newswww.helpnetsecurity.comDec 14, 2018, 7:00 AMThe popular Anarchy botmaster builds a botnet of 18,000 Huawei routers in a few hours, and it is also planning to target vulnerable Realtek routers. NewSky Security first reported the born a new huge botnet, in just one day the botmaster compromised more than 18,000 Huawei routers. NewSky security researcher Ankit Anubhav announced that the […]
newssecurityaffairs.comJul 20, 2018, 1:15 PMUnit 42 documents the emergence of three malware campaigns built on publicly available source code for the Mirai and Gafgyt malware families that incorporate multiple known exploits affecting Internet of Things (IoT) device.
vendorunit42.paloaltonetworks.comJul 20, 2018, 12:00 PMResearchers at security firm Radware have spotted a new IoT botnet, dubbed JenX, the leverages the Grand Theft Auto videogame community to infect devices. Researchers at security firm Radware have spotted a new IoT botnet, dubbed JenX, that exploits vulnerabilities triggered by the Satori botnet and is leveraging the Grand Theft Auto videogame community to infect devices. […]
newssecurityaffairs.comFeb 3, 2018, 11:59 AM- New Botnet Is Recruiting IoT DevicesSecurityWeek
A new botnet is recruiting Internet of Things (IoT) devices by exploiting two vulnerabilities already popular among IoT botnets, Radware has discovered.
newswww.securityweek.comFeb 2, 2018, 1:12 PM - IoT malware targeting zero-day vulnerabilitiesHelp Net Security
Once it became evident that IoT devices can be relatively easily enslaved in botnets and that even their limited power can be used for a variety of nefarious purposes, it was open season for malicious actors. First, they targeted IoT devices with default or weak passwords, and manufacturers and users began changing them. Then they used known vulnerabilities, and IoT vendor increased their efforts to push out patches. Now, some botmasters are making a concentrated … More →
newswww.helpnetsecurity.comJan 12, 2018, 8:41 PM Unit 42 researchers outline the evolution of Satori, a malware family targeting zero-day vulnerabilities in IoT devices
vendorunit42.paloaltonetworks.comJan 11, 2018, 11:00 AM- A flaw in Realtek SDK exposes SOHO routers to the attackSecurity Affairs
A flaw affecting Realtek SDK exposes SOHO routers to remote code execution attacks. List of vulnerable devices include D-Link and TRENDnet products. The security expert from DVLabs security researcher and content developer at HP Enterprise Security Ricky Lawshae discovered a (CVE-2014-8361) vulnerability that affects Realtek SDK used for RTL81xx chipsets. The exploitation of the vulnerability allows a […]
newssecurityaffairs.comApr 30, 2015, 6:35 AM Routers from D-Link, TRENDnet and likely other vendors are vulnerable to remote code execution attacks due to a flaw in a component of the Realtek software development kit (SDK).
newswww.securityweek.comApr 29, 2015, 12:32 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-2056CVSS 5.5 · Medium
A security vulnerability has been detected in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The impacted element is an unknown function of the file /wan_connection_status.asp of t…
- CVE-2026-2055CVSS 5.5 · Medium
A weakness has been identified in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. The affected element is an unknown function of the component DHCP Client Information Handler. Execu…
- CVE-2026-2054CVSS 5.5 · Medium
A security flaw has been discovered in D-Link DIR-605L and DIR-619L 2.06B01/2.13B01. Impacted is an unknown function of the component Wifi Setting Handler. Performing a manipulati…
- CVE-2026-42375CVSS 9.8 · Critical
D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetw…
- CVE-2026-42374CVSS 9.8 · Critical
D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetw…
- CVE-2026-42373CVSS 9.8 · Critical
D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alph…