PT-2021-5078 · Cisco · Rv016+5

Leetsun

·

Published

2021-11-03

·

Updated

2022-08-05

·

CVE-2021-40120

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Small Business RV016 versions (affected versions not specified) Cisco Small Business RV042 versions (affected versions not specified) Cisco Small Business RV042G versions (affected versions not specified) Cisco Small Business RV082 versions (affected versions not specified) Cisco Small Business RV320 versions (affected versions not specified) Cisco Small Business RV325 versions (affected versions not specified)
Description The issue is caused by insufficient validation of user-supplied input in the web-based management interface of certain Cisco Small Business RV Series Routers. This could allow a remote attacker with administrative privileges to inject arbitrary commands into the underlying operating system and execute them using root-level privileges. An attacker could exploit this by sending malicious input to a specific field in the web-based management interface of an affected device, potentially allowing the execution of arbitrary commands on the underlying Linux operating system as a user with root-level privileges.
Recommendations For Cisco Small Business RV016, update to a version that fixes the insufficient validation of user-supplied input. For Cisco Small Business RV042, update to a version that fixes the insufficient validation of user-supplied input. For Cisco Small Business RV042G, update to a version that fixes the insufficient validation of user-supplied input. For Cisco Small Business RV082, update to a version that fixes the insufficient validation of user-supplied input. For Cisco Small Business RV320, update to a version that fixes the insufficient validation of user-supplied input. For Cisco Small Business RV325, update to a version that fixes the insufficient validation of user-supplied input. As a temporary workaround, consider restricting access to the web-based management interface to minimize the risk of exploitation.

Fix

OS Command Injection

RCE

Weakness Enumeration

Related Identifiers

BDU:2021-05858
CVE-2021-40120

Affected Products

Rv016
Rv042
Rv042G
Rv082
Rv320
Rv325