cbcvebase.
CVE-2016-1396
published 2016-06-19

CVE-2016-1396: Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with…

medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCux82583.

Affected

13 ranges
VendorProductVersion rangeFixed in
ciscorv110w_rv130w_and_rv215w_routers
ciscorv110w_wireless-n_vpn_firewall_firmware
ciscorv110w_wireless-n_vpn_firewall_firmware
ciscorv110w_wireless-n_vpn_firewall_firmware
ciscorv110w_wireless-n_vpn_firewall_firmware
ciscorv130w_wireless-n_multifunction_vpn_router_firmware
ciscorv130w_wireless-n_multifunction_vpn_router_firmware
ciscorv130w_wireless-n_multifunction_vpn_router_firmware
ciscorv215w_wireless-n_vpn_router_firmware
ciscorv215w_wireless-n_vpn_router_firmware
ciscorv215w_wireless-n_vpn_router_firmware
ciscorv215w_wireless-n_vpn_router_firmware
ciscorv215w_wireless-n_vpn_router_firmware