← Back

CVE-2016-1396

nvd nist
Published: Jun 19, 2016Modified: May 6, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCux82583.

Affected (12)

3 products
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 1.0.0.21
Version 1.0.1.3
Version 1.0.2.7
Running on/withPlatform Versions
Cisco
Rv130w Wireless N Multifunction Vpn Router
All versions
Configuration B
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 1.1.0.9
Version 1.2.0.10
Version 1.2.0.9
Version 1.2.1.4
Running on/withPlatform Versions
Cisco
Rv110w Wireless N Vpn Firewall
All versions
Configuration C
5 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Cisco
Version 1.1.0.5
Version 1.1.0.6
Version 1.2.0.14
Version 1.2.0.15
Version 1.3.0.7
Running on/withPlatform Versions
Cisco
Rv215w Wireless N Vpn Router
All versions

References (4)

Timeline

No history available yet.