QID 731377
QID 731377: Cisco Small Business RV (016,042,042G,082) Routers Arbitrary Command Execution Vulnerability (cisco-sa-20191106-sbrv-cmd-x)
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must have either a valid credential or an active session token.
Affected Products
RV016 Multi-WAN VPN Router
RV042 Dual WAN VPN Router
RV042G Dual Gigabit WAN VPN Router
RV082 Dual WAN VPN Router
Note: Potential detection only checks for device model
QID Detection Logic (Unauthenticated):
The QID checks for the Vulnerable model of Cisco SMB RV router version retrieved via a GET request to a "login.html"
A successful exploit could allow the attacker to execute commands with root privileges.
Customers are advised to refer to cisco-sa-20191106-sbrv-cmd-x
- cisco-sa-20191106-sbrv-cmd-x -
sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20191106-sbrv-cmd-x
CVEs related to QID 731377
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| cisco-sa-20191106-sbrv-cmd-x |
|