PT-2018-1696 · Cisco · Cisco Rv215W Wireless-N Vpn Router+2

Published

2018-09-05

·

Updated

2020-08-28

·

CVE-2018-0424

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco RV110W Wireless-N VPN Firewall versions (affected versions not specified) Cisco RV130W Wireless-N Multifunction VPN Router versions (affected versions not specified) Cisco RV215W Wireless-N VPN Router versions (affected versions not specified)
Description The issue is related to insufficient input validation in the web-based management interface of the affected devices, allowing an attacker to execute arbitrary commands with root privileges by sending specially crafted requests. This could be done by exploiting the improper validation of user-supplied input to scripts by the web-based management interface.
Recommendations For Cisco RV110W Wireless-N VPN Firewall, update to a version that fixes the issue with improper validation of user-supplied input. For Cisco RV130W Wireless-N Multifunction VPN Router, update to a version that fixes the issue with improper validation of user-supplied input. For Cisco RV215W Wireless-N VPN Router, update to a version that fixes the issue with improper validation of user-supplied input. As a temporary workaround, consider restricting access to the web-based management interface to minimize the risk of exploitation.

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-01256
CVE-2018-0424

Affected Products

Cisco Rv110W Wireless-N Vpn Firewall
Cisco Rv130W Wireless-N Multifunction Vpn Router
Cisco Rv215W Wireless-N Vpn Router