QID 730586

Date Published: 2022-08-04

QID 730586: Cisco Small Business RV (160|260|340|345) Series Routers Vulnerabilities (cisco-sa-sb-mult-vuln-CbVp4SUR)

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device.

Affected Products
RV160 VPN Routers
RV160W Wireless-AC VPN Routers
RV260 VPN Routers
RV260P VPN Routers with PoE
RV260W Wireless-AC VPN Routers
RV340 Dual WAN Gigabit VPN Routers
RV340W Dual WAN Gigabit Wireless-AC VPN Routers
RV345 Dual WAN Gigabit VPN Routers
RV345P Dual WAN Gigabit POE VPN Routers
Note: Potential detection only checks for device model

QID Detection Logic (Unauthenticated):
The QID checks for the Vulnerable model of Cisco SMB RV router version retrieved via a GET request to a "login.html"

Successful exploitation could allow an unauthenticated, remote attacker to perform a command injection and execute commands on the underlying operating system with root privileges.

  • CVSS V3 rated as Critical - 10 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Customers are advised to refer to cisco-sa-sb-mult-vuln-CbVp4SUR for more information.

    CVEs related to QID 730586

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-sb-mult-vuln-CbVp4SUR URL Logo tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-mult-vuln-CbVp4SUR