Two new intrusion attempts: Remote Command Injection Activity 2 and Realtek SDK RCE CVE-2014-8361

I have been dealing with daily Zyxel Command Injection intrusion attempts, now I just got two new attempts both within seconds of each other:

1. First this attack happened:

An intrusion attempt by 178.72.75.118 was blocked

Category: Intrusion Prevention
Attack: Remote Command Injection Activity 2

Attacker URL: http://76.196.0.54:49152/soap.cgi?service=WANIPConn1

The attack was resulted from \DEVICE\HARDDISKVOLUME4\WINDOWS\SYSTEM32\WININIT.EXE.  

2.  Then this attack happened a few seconds later:

An intrusion attempt by 178.72.75.118 was blocked

Category: Intrusion Prevention
Web Attack: Realtek SDK RCE CVE-2014-8361


Attacker URL:  http://76.196.0.54:49152/soap.cgi?service=WANIPConn1
The attack was resulted from \DEVICE\HARDDISKVOLUME4\WINDOWS\SYSTEM32\WININIT.EXE.  

 

I am highly concerned and have some questions:

1. Is this related to the Zyxel Command Attacks?  Are they trying a new strategy now? The IP looks different.

2. What caused these attacks to happen?  How are so many people getting my IP address?  

3. What new vulnerability are they trying to exploit and what else can I do to minimize these attacks? (besides contacting my ISP or changing my devices)

 

 

 

Edit: 

WOPR:
I have been dealing with daily Zyxel Command Injection intrusion attempts,

~ reading WOPR here =>
https://community.norton.com/en/forums/zyxel-command-injection-cve-2023-28771

WOPR Activity Log
https://community.norton.com/en/user/20977246/activity-log

Does your modem/router/gateway receive security updates? 

Vulnerability Details : CVE-2014-8361
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

 

https://www.cvedetails.com/cve/CVE-2014-8361/


IP Abuse Reports for 178.72.75.118:

This IP address has been reported a total of 281 times from 29 distinct sources. 178.72.75.118 was first reported on February 24th 2021, and the most recent report was 3 months ago.

Old Reports: The most recent abuse report for this IP address is from 3 months ago. It is possible that this IP is no longer involved in abusive activities.

https://www.abuseipdb.com/check/178.72.75.118


IP Address Information For 178.72.75.118
https://ipwhoisinfo.com/ip/178.72.75.118


Attack: Remote Command Injection Activity 2
https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=31105

Web Attack: Realtek SDK RCE CVE-2014-8361
https://www.broadcom.com/support/security-center/attacksignatures/detail?asid=30495


How to Flush and Clear Windows DNS Cache - Nov 2021
https://www.lifewire.com/flush-and-clear-windows-dns-cache-5095298
Note: lifewire.com is supported by ads

How to Properly Restart a Router & Modem - June 2023
https://www.lifewire.com/how-to-properly-restart-a-router-modem-2624570
Note: lifewire.com is supported by ads


How to Secure Your Wi-Fi Router and Protect Your Home Network
https://www.wired.com/story/secure-your-wi-fi-router/
Note: wired.com is supported by ads


SetupRouter.com helps you make sense of your router - December 2022
https://setuprouter.com/
Note: setuprouter.com is supported by ads


Keep your home Wi-Fi safe in 7 simple steps
https://us.norton.com/blog/iot/keep-your-home-wifi-safe