cbcvebase.
CVE-2018-0424
published 2018-10-05

CVE-2018-0424: A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco…

PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.96%
89.2th percentile
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary commands. The vulnerability is due to improper validation of user-supplied input to scripts by the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the root user.

Affected

5 ranges
VendorProductVersion rangeFixed in
ciscocisco_rv130w_wireless-n_multifunction_vpn_router_firmware
ciscorv110w_firmware<= 1.2.1.7
ciscorv110w_rv130w_and_rv215w_routers
ciscorv130w_firmware< 1.0.3.441.0.3.44
ciscorv215w_firmware<= 1.3.0.8

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered via malicious HTTP requests to the web-based management interface scripts; monitor for anomalous or malformed POST/GET requests to management interface scripts on affected Cisco RV110W, RV130W, and RV215W devices
  • The root cause is improper validation of user-supplied input to scripts in the web management interface (CWE-78 OS Command Injection); look for shell metacharacters or command separators in HTTP request parameters destined for management interface scripts
  • Successful exploitation results in command execution as root; alert on unexpected processes spawned by the web server process (e.g., httpd spawning shell processes) on affected devices
  • ·Exploitation requires prior authentication; attack surface is limited to authenticated remote attackers, so enforcing strong credentials and restricting management interface access reduces exposure
  • ·No workarounds are available; the only remediation is applying Cisco's released software updates
  • ·Three distinct Cisco Bug IDs track this issue across the affected device families (RV110W, RV130W, RV215W); ensure patching is validated against all three

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.