CVE-2021-1459
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system of the affected device. Cisco has not released software updates that address this vulnerability.
Affected (4)
Products: Cisco: Rv110w Firmware, Rv130 Firmware, Rv130w Firmware, Rv215w Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.3.55 |
| Running on/with | Platform Versions |
|---|---|
Cisco Rv110w | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.3.55 |
| Running on/with | Platform Versions |
|---|---|
Cisco Rv130 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.3.55 |
| Running on/with | Platform Versions |
|---|---|
Cisco Rv130w | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.3.55 |
| Running on/with | Platform Versions |
|---|---|
Cisco Rv215w | All versions |
Related CWEs
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
References (2)
Source: psirt@cisco.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.