PT-2018-2138 · Cisco · Cisco Small Business Rv Series Rv220W Wireless Network Security Firewall+1

Published

2018-10-05

·

Updated

2019-10-09

·

CVE-2018-0404

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco RV180W Wireless-N Multifunction VPN Router (affected versions not specified) Cisco Small Business RV Series RV220W Wireless Network Security Firewall (affected versions not specified)
Description The issue is related to the lack of protection against SQL query structure exploitation in the web framework code. This could allow a remote attacker to execute arbitrary SQL queries and retrieve sensitive information that should be restricted.
Recommendations For Cisco RV180W Wireless-N Multifunction VPN Router, consider restricting access to the web framework until a resolution is available, however, since the product has entered the end-of-life phase, no firmware fixes will be provided. For Cisco Small Business RV Series RV220W Wireless Network Security Firewall, consider restricting access to the web framework until a resolution is available, however, since the product has entered the end-of-life phase, no firmware fixes will be provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00090
CVE-2018-0404

Affected Products

Cisco Rv180W Wireless-N Multifunction Vpn Router
Cisco Small Business Rv Series Rv220W Wireless Network Security Firewall