QID 730899

Date Published: 2023-09-20

QID 730899: Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Stack Overflow Vulnerability (cisco-sa-sb-rv-stack-SHYv2f5N)

A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device.

Affected Products:
RV110W Wireless-N VPN Firewall
RV130 VPN Router
RV130W Wireless-N Multifunction VPN Router
RV215W Wireless-N VPN Router

QID Detection Logic (Unauthenticated):
This QID checks for affected products by sending a HTTP GET request to '/' endpoint.

A successful exploit could allow the attacker to execute arbitrary code with root privileges on an affected device.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as Low - 2.6 severity.
  • Solution
    All the affected products have reached end of life, Cisco will not be releasing patches to address the vulnerability. For more information pertaining to the vulnerability please refer to cisco-sa-sb-rv-stack-SHYv2f5N

    CVEs related to QID 730899

    Software Advisories
    Advisory ID Software Component Link
    cisco-sa-sb-rv-stack-SHYv2f5N URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-stack-SHYv2f5N