QID 730347
Date Published: 2022-02-10
QID 730347: Cisco Small Business RV (340|345) Series Routers Vulnerabilities (cisco-sa-smb-mult-vuln-KA9PK6D)
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following:
Execute arbitrary code
Elevate privileges
Execute arbitrary commands
Bypass authentication and authorization protections
Fetch and run unsigned software
Cause denial of service (DoS)
Affected Products
Following Cisco Small Buisness RV Routers:
RV340 Dual WAN Gigabit VPN Routers
RV340W Dual WAN Gigabit Wireless-AC VPN Routers
RV345 Dual WAN Gigabit VPN Routers
RV345P Dual WAN Gigabit POE VPN Routers
Vulnerable version : 1.0.03.24
Fix version: 1.0.03.26
Note: Potential detection only checks for device model
QID Detection Logic (Unauthenticated):
The QID checks for the Vulnerable model of Cisco SMB RV router version retrieved via a GET request to a "login.html"
On Successful exploitation the attacker would be able to take over the device.
Customers are advised to refer to cisco-sa-smb-mult-vuln-KA9PK6D for more information.
- cisco-sa-smb-mult-vuln-KA9PK6D -
tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-smb-mult-vuln-KA9PK6D
CVEs related to QID 730347
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-smb-mult-vuln-KA9PK6D |
|