CVE-2021-1146
Published on: 01/13/2021 12:00:00 AM UTC
Last Modified on: 08/05/2022 07:27:00 PM UTC
CVE-2021-1146 - advisory for cisco-sa-rv-command-inject-LBdQ2KRN
Source: Mitre Source: NIST CVE.ORG Print: PDF
Certain versions of Application Extension Platform from Cisco contain the following vulnerability:
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on an affected device. Cisco has not released software updates that address these vulnerabilities.
- CVE-2021-1146 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory.
- Affected Vendor/Software:
Cisco - Cisco Small Business RV Series Router Firmware version n/a
CVSS3 Score: 7.2 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 9 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Command Injection Vulnerabilities | Vendor Advisory tools.cisco.com text/html |
![]() |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Cisco | Application Extension Platform | 1.0.3.55 | All | All | All |
Application | Cisco | Application Extension Platform | 1.0.3.55 | All | All | All |
Hardware
| Cisco | Rv110w | - | All | All | All |
Hardware
| Cisco | Rv110w | - | All | All | All |
Hardware
| Cisco | Rv110w | - | All | All | All |
Operating System | Cisco | Rv110w Firmware | 1.2.2.8 | All | All | All |
Operating System | Cisco | Rv110w Firmware | 1.3.1.7 | All | All | All |
Operating System | Cisco | Rv110w Firmware | 1.2.2.8 | All | All | All |
Operating System | Cisco | Rv110w Firmware | 1.3.1.7 | All | All | All |
Hardware
| Cisco | Rv130w | - | All | All | All |
Hardware
| Cisco | Rv130w | - | All | All | All |
Hardware
| Cisco | Rv130w | - | All | All | All |
Operating System | Cisco | Rv130w Firmware | 1.2.2.8 | All | All | All |
Operating System | Cisco | Rv130w Firmware | 1.3.1.7 | All | All | All |
Operating System | Cisco | Rv130w Firmware | 1.2.2.8 | All | All | All |
Operating System | Cisco | Rv130w Firmware | 1.3.1.7 | All | All | All |
Hardware
| Cisco | Rv130 Vpn Router | - | All | All | All |
Hardware
| Cisco | Rv130 Vpn Router | - | All | All | All |
Hardware
| Cisco | Rv130 Vpn Router | - | All | All | All |
Operating System | Cisco | Rv130 Vpn Router Firmware | 1.2.2.8 | All | All | All |
Operating System | Cisco | Rv130 Vpn Router Firmware | 1.3.1.7 | All | All | All |
Operating System | Cisco | Rv130 Vpn Router Firmware | 1.2.2.8 | All | All | All |
Operating System | Cisco | Rv130 Vpn Router Firmware | 1.3.1.7 | All | All | All |
Hardware
| Cisco | Rv215w Wireless-n Vpn Router | - | All | All | All |
Hardware
| Cisco | Rv215w Wireless-n Vpn Router | - | All | All | All |
Hardware
| Cisco | Rv215w Wireless-n Vpn Router | - | All | All | All |
Operating System | Cisco | Rv215w Wireless-n Vpn Router Firmware | 1.2.2.8 | All | All | All |
Operating System | Cisco | Rv215w Wireless-n Vpn Router Firmware | 1.3.1.7 | All | All | All |
Operating System | Cisco | Rv215w Wireless-n Vpn Router Firmware | 1.2.2.8 | All | All | All |
Operating System | Cisco | Rv215w Wireless-n Vpn Router Firmware | 1.3.1.7 | All | All | All |
- cpe:2.3:a:cisco:application_extension_platform:1.0.3.55:*:*:*:*:*:*:*:
- cpe:2.3:a:cisco:application_extension_platform:1.0.3.55:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:rv110w:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:rv110w:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:rv110w:-:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:rv110w_firmware:1.2.2.8:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:rv110w_firmware:1.3.1.7:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:rv110w_firmware:1.2.2.8:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:rv110w_firmware:1.3.1.7:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:rv130w:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:rv130w:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:rv130w:-:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:rv130w_firmware:1.2.2.8:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:rv130w_firmware:1.3.1.7:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:rv130w_firmware:1.2.2.8:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:rv130w_firmware:1.3.1.7:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:rv130_vpn_router:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:rv130_vpn_router:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:rv130_vpn_router:-:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:rv130_vpn_router_firmware:1.2.2.8:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:rv130_vpn_router_firmware:1.3.1.7:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:rv130_vpn_router_firmware:1.2.2.8:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:rv130_vpn_router_firmware:1.3.1.7:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:rv215w_wireless-n_vpn_router:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:rv215w_wireless-n_vpn_router:-:*:*:*:*:*:*:*:
- cpe:2.3:h:cisco:rv215w_wireless-n_vpn_router:-:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:1.2.2.8:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:1.3.1.7:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:1.2.2.8:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:1.3.1.7:*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
Severity: ??? | Multiple vulnerabilities in the web-base... | CVE-2021-1146 | Link for more: alerts.remotelyrmm.com/CVE-2021-1146 | 2022-08-05 20:29:59 |