CVE-2021-1459

Published on: 04/08/2021 12:00:00 AM UTC

Last Modified on: 04/08/2021 11:26:00 AM UTC

CVE-2021-1459 - advisory for cisco-sa-rv-rce-q3rxHnvm

Source: Mitre
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Certain versions of Rv110w from Cisco contain the following vulnerability:

A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system of the affected device. Cisco has not released software updates that address this vulnerability.

  • CVE-2021-1459 has been assigned by [email protected] to track the vulnerability
  • The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory.
  • Affected Vendor/Software: Cisco - Cisco Small Business RV Series Router Firmware version n/a

CVE References

Description Tags Link
Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability tools.cisco.com
text/html
URL Logo CISCO 20210407 Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
HardwareCiscoRv110w-AllAllAll
Operating
System
CiscoRv110w Firmware1.0.3.55AllAllAll
HardwareCiscoRv130-AllAllAll
HardwareCiscoRv130w-AllAllAll
Operating
System
CiscoRv130w Firmware1.0.3.55AllAllAll
Operating
System
CiscoRv130 Firmware1.0.3.55AllAllAll
HardwareCiscoRv215w-AllAllAll
Operating
System
CiscoRv215w Firmware1.0.3.55AllAllAll
  • cpe:2.3:h:cisco:rv110w:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:cisco:rv110w_firmware:1.0.3.55:*:*:*:*:*:*:*:
  • cpe:2.3:h:cisco:rv130:-:*:*:*:*:*:*:*:
  • cpe:2.3:h:cisco:rv130w:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:cisco:rv130w_firmware:1.0.3.55:*:*:*:*:*:*:*:
  • cpe:2.3:o:cisco:rv130_firmware:1.0.3.55:*:*:*:*:*:*:*:
  • cpe:2.3:h:cisco:rv215w:-:*:*:*:*:*:*:*:
  • cpe:2.3:o:cisco:rv215w_firmware:1.0.3.55:*:*:*:*:*:*:*:

Social Mentions

Source Title Posted (UTC)
Twitter Icon @CVEreport CVE-2021-1459 : A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130… twitter.com/i/web/status/1… 2021-04-08 04:21:36
Twitter Icon @autumn_good_35 『By default, the remote management feature is disabled on these devices.』 CVE-2021-1459 Cisco Small Business RV110… twitter.com/i/web/status/1… 2021-04-08 09:55:54
Twitter Icon @csirt_it #Cisco: individuata vulnerabilità critica (CVE-2021-1459) su firewall e router a fine ciclo di vita (EOL) Rischio:… twitter.com/i/web/status/1… 2021-04-08 14:34:19
Twitter Icon @SystemTek_UK Cisco Small Business Routers Management Interface Remote Command Execution Vulnerability [CVE-2021-1459] systemtek.co.uk/2021/04/cisco-… 2021-04-08 16:07:08
Twitter Icon @6townstechteam Cisco Small Business Routers Management Interface Remote Command Execution Vulnerability [CVE-2021-1459] systemtek.co.uk/2021/04/cisco-… 2021-04-08 16:07:08
Twitter Icon @NCIIPC Critical Remote Command Execution (#RCE) vulnerability #CVE-2021-1459 has been found in selected #Cisco Small Busin… twitter.com/i/web/status/1… 2021-04-09 08:57:22
Twitter Icon @SiliconShecky Got an Small Business RV130, RV130W, and RV215W router from @Cisco ? RCE Flaw CVE-2021-1459 will not be patched. EO… twitter.com/i/web/status/1… 2021-04-09 13:22:47
Twitter Icon @BSSI_Conseil La CVE-2021-1459 affectant les équipements RV110W VPN firewall, Small Business RV130, RV130W, et les routeurs RV215… twitter.com/i/web/status/1… 2021-04-11 08:53:26