PT-2018-2138 · Cisco · Cisco Small Business Rv Series Rv220W Wireless Network Security Firewall+1
Published
2018-10-05
·
Updated
2019-10-09
·
CVE-2018-0404
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco RV180W Wireless-N Multifunction VPN Router (affected versions not specified)
Cisco Small Business RV Series RV220W Wireless Network Security Firewall (affected versions not specified)
Description
The issue is related to the lack of protection against SQL query structure exploitation in the web framework code. This could allow a remote attacker to execute arbitrary SQL queries and retrieve sensitive information that should be restricted.
Recommendations
For Cisco RV180W Wireless-N Multifunction VPN Router, consider restricting access to the web framework until a resolution is available, however, since the product has entered the end-of-life phase, no firmware fixes will be provided.
For Cisco Small Business RV Series RV220W Wireless Network Security Firewall, consider restricting access to the web framework until a resolution is available, however, since the product has entered the end-of-life phase, no firmware fixes will be provided.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Rv180W Wireless-N Multifunction Vpn Router
Cisco Small Business Rv Series Rv220W Wireless Network Security Firewall