PT-2022-3868 · Cisco · Cisco Small Business Rv130W Wireless-N Multifunction Vpn Router+3

Chuan Qin

+2

·

Published

2022-07-20

·

Updated

2022-07-28

·

CVE-2022-20910

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Small Business RV110W Wireless-N VPN Firewall versions not specified Cisco Small Business RV130 Series VPN Router versions not specified Cisco Small Business RV130W Wireless-N Multifunction VPN Router versions not specified Cisco Small Business RV215W Wireless-N VPN Router versions not specified
Description The issue is related to insufficient validation of user fields within incoming HTTP packets in the web-based management interface. This could allow a remote attacker with valid Administrator credentials to execute arbitrary commands on an affected device or cause the device to restart unexpectedly, resulting in a denial of service (DoS) condition. The attacker could exploit this by sending a crafted request to the web-based management interface.
Recommendations For Cisco Small Business RV110W Wireless-N VPN Firewall, restrict access to the web-based management interface until a fix is available. For Cisco Small Business RV130 Series VPN Router, consider disabling remote management capabilities to minimize the risk of exploitation. For Cisco Small Business RV130W Wireless-N Multifunction VPN Router, avoid using the web-based management interface for critical operations until the issue is resolved. For Cisco Small Business RV215W Wireless-N VPN Router, limit access to the device to only necessary personnel to reduce the risk of unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04671
CVE-2022-20910

Affected Products

Cisco Small Business Rv110W Wireless-N Vpn Firewall
Cisco Small Business Rv130 Series Vpn Router
Cisco Small Business Rv130W Wireless-N Multifunction Vpn Router
Cisco Small Business Rv215W Wireless-N Vpn Router