CVE-2014-2178Cross-Site Request Forgery in Cisco Rv120w Firmware

Severity
6.8MEDIUMNVD
EPSS
0.3%
top 44.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 7
Latest updateMay 14

Description

Cross-site request forgery (CSRF) vulnerability in the administrative web interface in the Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote attackers to hijack the authentication of administrators, aka Bug ID CSCuh87145.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages3 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x77r-9j3c-w6wj: Cross-site request forgery (CSRF) vulnerability in the administrative web interface in the Cisco RV router firmware on RV220W devices, before 12022-05-14
CVEList
CVE-2014-2178: Cross-site request forgery (CSRF) vulnerability in the administrative web interface in the Cisco RV router firmware on RV220W devices, before 12014-11-07

📋Vendor Advisories

2
Cisco
Multiple Vulnerabilities in Cisco Small Business RV Series Routers2014-11-06
Cisco
Cisco Small Business RV Series Routers HTTP Referer Header Vulnerability2014-11-05
CVE-2014-2178 — Cross-Site Request Forgery in Cisco | cvebase