CVE-2018-0426
Cisco RV110W, RV130W, and RV215W Routers Management Interface Directory Traversal Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character sequences within the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to the targeted device. A successful exploit could allow the attacker to gain access to arbitrary files on the affected device, resulting in the disclosure of sensitive information.
Una vulnerabilidad en la interfaz de gestión web de los dispositivos Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router y Cisco RV215W Wireless-N VPN Router podría permitir que un atacante remoto no autenticado obtenga información sensible. La vulnerabilidad se debe a la validación insuficiente de secuencias de caracteres de salto de directorio en la interfaz de gestión web. Un atacante podría explotar esta vulnerabilidad mediante el envío de peticiones maliciosas al dispositivo objetivo. Su explotación con éxito podría permitir que el atacante obtenga acceso a archivos arbitrarios en el dispositivo afectado, resultando en una divulgación de información sensible.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-11-27 CVE Reserved
- 2018-10-05 CVE Published
- 2024-06-20 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1041678 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Rv110w Firmware Search vendor "Cisco" for product "Rv110w Firmware" | <= 1.2.1.7 Search vendor "Cisco" for product "Rv110w Firmware" and version " <= 1.2.1.7" | - |
Affected
| in | Cisco Search vendor "Cisco" | Rv110w Wireless-n Vpn Firewall Search vendor "Cisco" for product "Rv110w Wireless-n Vpn Firewall" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Rv130w Firmware Search vendor "Cisco" for product "Rv130w Firmware" | < 1.0.3.44 Search vendor "Cisco" for product "Rv130w Firmware" and version " < 1.0.3.44" | - |
Affected
| in | Cisco Search vendor "Cisco" | Rv130w Search vendor "Cisco" for product "Rv130w" | * | - |
Safe
|
Cisco Search vendor "Cisco" | Rv215w Firmware Search vendor "Cisco" for product "Rv215w Firmware" | <= 1.3.0.8 Search vendor "Cisco" for product "Rv215w Firmware" and version " <= 1.3.0.8" | - |
Affected
| in | Cisco Search vendor "Cisco" | Rv215w Wireless-n Vpn Router Search vendor "Cisco" for product "Rv215w Wireless-n Vpn Router" | - | - |
Safe
|