PT-2021-5078 · Cisco · Rv016+5
Leetsun
·
Published
2021-11-03
·
Updated
2022-08-05
·
CVE-2021-40120
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco Small Business RV016 versions (affected versions not specified)
Cisco Small Business RV042 versions (affected versions not specified)
Cisco Small Business RV042G versions (affected versions not specified)
Cisco Small Business RV082 versions (affected versions not specified)
Cisco Small Business RV320 versions (affected versions not specified)
Cisco Small Business RV325 versions (affected versions not specified)
Description
The issue is caused by insufficient validation of user-supplied input in the web-based management interface of certain Cisco Small Business RV Series Routers. This could allow a remote attacker with administrative privileges to inject arbitrary commands into the underlying operating system and execute them using root-level privileges. An attacker could exploit this by sending malicious input to a specific field in the web-based management interface of an affected device, potentially allowing the execution of arbitrary commands on the underlying Linux operating system as a user with root-level privileges.
Recommendations
For Cisco Small Business RV016, update to a version that fixes the insufficient validation of user-supplied input.
For Cisco Small Business RV042, update to a version that fixes the insufficient validation of user-supplied input.
For Cisco Small Business RV042G, update to a version that fixes the insufficient validation of user-supplied input.
For Cisco Small Business RV082, update to a version that fixes the insufficient validation of user-supplied input.
For Cisco Small Business RV320, update to a version that fixes the insufficient validation of user-supplied input.
For Cisco Small Business RV325, update to a version that fixes the insufficient validation of user-supplied input.
As a temporary workaround, consider restricting access to the web-based management interface to minimize the risk of exploitation.
Fix
OS Command Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rv016
Rv042
Rv042G
Rv082
Rv320
Rv325