cbcvebase.
CVE-2016-1395
published 2016-06-19

CVE-2016-1395: The web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with…

PriorityP266critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.81%
91.0th percentile
The web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote attackers to execute arbitrary code as root via a crafted HTTP request, aka Bug ID CSCux82428.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
ciscorv110w_rv130w_and_rv215w_routers
ciscorv110w_wireless-n_vpn_firewall_firmware
ciscorv110w_wireless-n_vpn_firewall_firmware
ciscorv110w_wireless-n_vpn_firewall_firmware
ciscorv110w_wireless-n_vpn_firewall_firmware
ciscorv130w_wireless-n_multifunction_vpn_router_firmware
ciscorv130w_wireless-n_multifunction_vpn_router_firmware
ciscorv130w_wireless-n_multifunction_vpn_router_firmware
ciscorv215w_wireless-n_vpn_router_firmware
ciscorv215w_wireless-n_vpn_router_firmware
ciscorv215w_wireless-n_vpn_router_firmware
ciscorv215w_wireless-n_vpn_router_firmware
ciscorv215w_wireless-n_vpn_router_firmware
msrcmicrosoft_office
msrcwindows_10
msrcwindows_10_version_1607
msrcwindows_10_version_1809
msrcwindows_10_version_21h2
msrcwindows_10_version_22h2
msrcwindows_11_version_22h2
msrcwindows_11_version_23h2
msrcwindows_11_version_24h2
msrcwindows_11_version_25h2
msrcwindows_server_2008
msrcwindows_server_2008_r2

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is an unauthenticated crafted HTTP request with custom user data sent to the web-based management interface; monitor for anomalous or oversized HTTP requests to the router management interface from untrusted sources.
  • The vulnerability is due to insufficient sanitization of HTTP user-supplied input; inspect HTTP request parameters destined at the management interface of Cisco RV110W, RV130W, and RV215W devices for unsanitized/malformed input patterns.
  • Successful exploitation results in arbitrary code execution as root; alert on unexpected root-level process spawning from the web server process on affected devices.
  • ·Cisco RV110W devices are vulnerable only if running firmware versions prior to 1.2.1.7.
  • ·Cisco RV130W devices are vulnerable only if running firmware versions prior to 1.0.3.16.
  • ·Cisco RV215W devices are vulnerable only if running firmware versions prior to 1.3.0.8.
  • ·No workarounds are available for this vulnerability; patching via firmware update is the only remediation.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
vendor_msrc4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.