CVE-2018-0424
published 2018-10-05CVE-2018-0424: A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco…
PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.96%
89.2th percentile
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary commands. The vulnerability is due to improper validation of user-supplied input to scripts by the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the root user.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_rv130w_wireless-n_multifunction_vpn_router_firmware | — | — |
| cisco | rv110w_firmware | <= 1.2.1.7 | — |
| cisco | rv110w_rv130w_and_rv215w_routers | — | — |
| cisco | rv130w_firmware | < 1.0.3.44 | 1.0.3.44 |
| cisco | rv215w_firmware | <= 1.3.0.8 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is triggered via malicious HTTP requests to the web-based management interface scripts; monitor for anomalous or malformed POST/GET requests to management interface scripts on affected Cisco RV110W, RV130W, and RV215W devices ↗
- →The root cause is improper validation of user-supplied input to scripts in the web management interface (CWE-78 OS Command Injection); look for shell metacharacters or command separators in HTTP request parameters destined for management interface scripts ↗
- →Successful exploitation results in command execution as root; alert on unexpected processes spawned by the web server process (e.g., httpd spawning shell processes) on affected devices ↗
- ·Exploitation requires prior authentication; attack surface is limited to authenticated remote attackers, so enforcing strong credentials and restricting management interface access reduces exposure ↗
- ·No workarounds are available; the only remediation is applying Cisco's released software updates ↗
- ·Three distinct Cisco Bug IDs track this issue across the affected device families (RV110W, RV130W, RV215W); ensure patching is validated against all three ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco RV110W, RV130W, and RV215W Routers Management Interface Command Injection Vulnerability
vendor_cisco·2018-09-05·CVSS 7.2
CVE-2018-0424 [HIGH] CWE-78 Cisco RV110W, RV130W, and RV215W Routers Management Interface Command Injection Vulnerability
Cisco RV110W, RV130W, and RV215W Routers Management Interface Command Injection Vulnerability
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary commands.
The vulnerability is due to improper validation of user-supplied input to scripts by the web-based management interface. An attacker could exploit this
vulnerability by sending malicious requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the root user.
Cisco has released software updates that address this vulnerability. There are no workarounds that address t
Cisco
Cisco RV110W, RV130W, and RV215W Routers Management Interface Command Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0424 Cisco RV110W, RV130W, and RV215W Routers Management Interface Command Injection Vulnerability
CVE-2018-0424: Cisco RV110W, RV130W, and RV215W Routers Management Interface Command Injection Vulnerability
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary commands. The vulnerability is due to improper validation of user-supplied input to scripts by the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the root user. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CW
GHSA
GHSA-mm33-w43h-6m3f: A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, a
ghsa_unreviewed·2022-05-13
CVE-2018-0424 [HIGH] CWE-78 GHSA-mm33-w43h-6m3f: A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, a
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary commands. The vulnerability is due to improper validation of user-supplied input to scripts by the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the root user.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-10-05
Published