""ET EXPLOIT Realtek SDK Miniigd UPnP SOAP Command Execution CVE-2014-8361""

SID: 2025132

Revision: 3

Class Type: attempted-user

Metadata: attack_target IoT, created_at 2017_12_05, updated_at 2018_06_18

Reference:

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: $HOME_NET

Destination Port: 52869

Flow: established,to_server

Contents:

  • Value: "POST /picdesc.xml"

  • Value: "SOAPAction|3a 20|urn|3a|schemas-upnp-org|3a|service|3a|WANIPConnection|3a|"

Within:

PCRE:

Special Options:

source