Vulnerability Details : CVE-2021-1150


CVE Name: CVE-2021-1150: Code Execution vulnerability on Cisco Rv110W Firmware, Cisco Rv110W, Cisco Rv130 Vpn Router Firmware, Cisco Rv130 Vpn Router, Cisco Rv130W Firmware, Cisco Rv130W, Cisco Rv215W Wireless N Vpn Router Firmware, Cisco Rv215W Wireless N Vpn Router, Cisco Application Extension Platform
Description: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privileges. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on an affected device. Cisco has not released software updates that address these vulnerabilities.
Publish date: 2021-01-13T22:15Z
Last Update: 2022-08-05T19:27Z

CVSS Scores & Vulnerability Types


CVSS Score
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH
Actack VectorNETWORK
Actack ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
ScopeUNCHANGED
Vulnerability Type(s)Code Execution
CWE ID78

Detail of Verions Affected


# Product Type Vendor Product Version
1 Operating System Cisco Rv110W Firmware 1.3.1.7
2 Operating System Cisco Rv110W Firmware 1.2.2.8
3 Hardware Cisco Rv110W
4 Operating System Cisco Rv130 Vpn Router Firmware 1.3.1.7
5 Operating System Cisco Rv130 Vpn Router Firmware 1.2.2.8
6 Hardware Cisco Rv130 Vpn Router
7 Operating System Cisco Rv130W Firmware 1.3.1.7
8 Operating System Cisco Rv130W Firmware 1.2.2.8
9 Hardware Cisco Rv130W
10 Operating System Cisco Rv215W Wireless N Vpn Router Firmware 1.3.1.7
11 Operating System Cisco Rv215W Wireless N Vpn Router Firmware 1.2.2.8
12 Hardware Cisco Rv215W Wireless N Vpn Router
13 Application Cisco Application Extension Platform 1.0.3.55