CVE-2021-1472
Cisco Small Business RV Series Routers Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Se presentan múltiples vulnerabilidades en la interfaz de administración basada en web de los enrutadores Cisco Small Business RV Series. Un atacante remoto podría ejecutar comandos arbitrarios u omitir la autenticación y cargar archivos en un dispositivo afectado. Para mayor información sobre estas vulnerabilidades, consulte la sección Detalles de este aviso
Cisco RV-series routers suffer from an authentication bypass vulnerability. The RV34X series are also affected by a command injection vulnerability in the sessionid cookie, when requesting the /upload endpoint. A combination of these issues would allow any person who is able to communicate with the web interface to run arbitrary system commands on the router as the www-data user. Vulnerable versions include RV16X/RV26X versions 1.0.01.02 and below and RV34X versions 1.0.03.20 and below.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2020-11-13 CVE Reserved
- 2021-04-08 CVE Published
- 2024-10-16 EPSS Updated
- 2024-11-08 CVE Updated
- 2024-11-08 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-287: Improper Authentication
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2021/Apr/39 | Mailing List |
URL | Date | SRC |
---|---|---|
http://packetstormsecurity.com/files/162238/Cisco-RV-Authentication-Bypass-Code-Execution.html | 2024-11-08 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Rv160 Firmware Search vendor "Cisco" for product "Rv160 Firmware" | < 1.0.01.03 Search vendor "Cisco" for product "Rv160 Firmware" and version " < 1.0.01.03" | - |
Affected
| in | Cisco Search vendor "Cisco" | Rv160 Search vendor "Cisco" for product "Rv160" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Rv160w Firmware Search vendor "Cisco" for product "Rv160w Firmware" | < 1.0.01.03 Search vendor "Cisco" for product "Rv160w Firmware" and version " < 1.0.01.03" | - |
Affected
| in | Cisco Search vendor "Cisco" | Rv160w Search vendor "Cisco" for product "Rv160w" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Rv260 Firmware Search vendor "Cisco" for product "Rv260 Firmware" | < 1.0.01.03 Search vendor "Cisco" for product "Rv260 Firmware" and version " < 1.0.01.03" | - |
Affected
| in | Cisco Search vendor "Cisco" | Rv260 Search vendor "Cisco" for product "Rv260" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Rv260p Firmware Search vendor "Cisco" for product "Rv260p Firmware" | < 1.0.01.03 Search vendor "Cisco" for product "Rv260p Firmware" and version " < 1.0.01.03" | - |
Affected
| in | Cisco Search vendor "Cisco" | Rv260p Search vendor "Cisco" for product "Rv260p" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Rv260w Firmware Search vendor "Cisco" for product "Rv260w Firmware" | < 1.0.01.03 Search vendor "Cisco" for product "Rv260w Firmware" and version " < 1.0.01.03" | - |
Affected
| in | Cisco Search vendor "Cisco" | Rv260w Search vendor "Cisco" for product "Rv260w" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Rv340 Firmware Search vendor "Cisco" for product "Rv340 Firmware" | < 1.0.03.21 Search vendor "Cisco" for product "Rv340 Firmware" and version " < 1.0.03.21" | - |
Affected
| in | Cisco Search vendor "Cisco" | Rv340 Search vendor "Cisco" for product "Rv340" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Rv340w Firmware Search vendor "Cisco" for product "Rv340w Firmware" | < 1.0.03.21 Search vendor "Cisco" for product "Rv340w Firmware" and version " < 1.0.03.21" | - |
Affected
| in | Cisco Search vendor "Cisco" | Rv340w Search vendor "Cisco" for product "Rv340w" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Rv345 Firmware Search vendor "Cisco" for product "Rv345 Firmware" | < 1.0.03.21 Search vendor "Cisco" for product "Rv345 Firmware" and version " < 1.0.03.21" | - |
Affected
| in | Cisco Search vendor "Cisco" | Rv345 Search vendor "Cisco" for product "Rv345" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Rv345p Firmware Search vendor "Cisco" for product "Rv345p Firmware" | < 1.0.03.21 Search vendor "Cisco" for product "Rv345p Firmware" and version " < 1.0.03.21" | - |
Affected
| in | Cisco Search vendor "Cisco" | Rv345p Search vendor "Cisco" for product "Rv345p" | - | - |
Safe
|