CVE-2016-1395
published 2016-06-19CVE-2016-1395: The web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with…
PriorityP266critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.81%
91.0th percentile
The web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote attackers to execute arbitrary code as root via a crafted HTTP request, aka Bug ID CSCux82428.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | rv110w_rv130w_and_rv215w_routers | — | — |
| cisco | rv110w_wireless-n_vpn_firewall_firmware | — | — |
| cisco | rv110w_wireless-n_vpn_firewall_firmware | — | — |
| cisco | rv110w_wireless-n_vpn_firewall_firmware | — | — |
| cisco | rv110w_wireless-n_vpn_firewall_firmware | — | — |
| cisco | rv130w_wireless-n_multifunction_vpn_router_firmware | — | — |
| cisco | rv130w_wireless-n_multifunction_vpn_router_firmware | — | — |
| cisco | rv130w_wireless-n_multifunction_vpn_router_firmware | — | — |
| cisco | rv215w_wireless-n_vpn_router_firmware | — | — |
| cisco | rv215w_wireless-n_vpn_router_firmware | — | — |
| cisco | rv215w_wireless-n_vpn_router_firmware | — | — |
| cisco | rv215w_wireless-n_vpn_router_firmware | — | — |
| cisco | rv215w_wireless-n_vpn_router_firmware | — | — |
| msrc | microsoft_office | — | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_10_version_22h2 | — | — |
| msrc | windows_11_version_22h2 | — | — |
| msrc | windows_11_version_23h2 | — | — |
| msrc | windows_11_version_24h2 | — | — |
| msrc | windows_11_version_25h2 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_r2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector is an unauthenticated crafted HTTP request with custom user data sent to the web-based management interface; monitor for anomalous or oversized HTTP requests to the router management interface from untrusted sources. ↗
- →The vulnerability is due to insufficient sanitization of HTTP user-supplied input; inspect HTTP request parameters destined at the management interface of Cisco RV110W, RV130W, and RV215W devices for unsanitized/malformed input patterns. ↗
- →Successful exploitation results in arbitrary code execution as root; alert on unexpected root-level process spawning from the web server process on affected devices. ↗
- ·Cisco RV110W devices are vulnerable only if running firmware versions prior to 1.2.1.7. ↗
- ·Cisco RV130W devices are vulnerable only if running firmware versions prior to 1.0.3.16. ↗
- ·Cisco RV215W devices are vulnerable only if running firmware versions prior to 1.3.0.8. ↗
- ·No workarounds are available for this vulnerability; patching via firmware update is the only remediation. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
vendor_msrc4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco RV110W, RV130W, and RV215W Routers Arbitrary Code Execution Vulnerability
vendor_cisco·2016-06-15·CVSS 10.0
CVE-2016-1395 [CRITICAL] CWE-20 Cisco RV110W, RV130W, and RV215W Routers Arbitrary Code Execution Vulnerability
Cisco RV110W, RV130W, and RV215W Routers Arbitrary Code Execution Vulnerability
A vulnerability in the web interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code as root on a targeted system.
The vulnerability is due to insufficient sanitization of HTTP user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request with custom user data. An exploit could allow the attacker to execute arbitrary code with root-level privileges on the affected system, which could be leveraged to conduct further attacks.
Cisco has released firmware updates that address this vulnerability. Workarounds that addre
Cisco
Cisco RV110W, RV130W, and RV215W Routers Arbitrary Code Execution Vulnerability
vendor_cisco
CVE-2016-1395 Cisco RV110W, RV130W, and RV215W Routers Arbitrary Code Execution Vulnerability
CVE-2016-1395: Cisco RV110W, RV130W, and RV215W Routers Arbitrary Code Execution Vulnerability
A vulnerability in the web interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code as root on a targeted system. The vulnerability is due to insufficient sanitization of HTTP user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request with custom user data. An exploit could allow the attacker to execute arbitrary code with root -level privileges on the affected system, which could be leveraged to conduct further attacks. Cisco has released firmware updates that address this vulnerability.
CWE: CWE-
GHSA
GHSA-jwxc-84mj-872v: The web-based management interface on Cisco RV110W devices with firmware before 1
ghsa_unreviewed·2022-05-17
CVE-2016-1395 [CRITICAL] CWE-20 GHSA-jwxc-84mj-872v: The web-based management interface on Cisco RV110W devices with firmware before 1
The web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote attackers to execute arbitrary code as root via a crafted HTTP request, aka Bug ID CSCux82428.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-06-19
Published