CVE-2018-0425
published 2018-10-05CVE-2018-0425: A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco…
PriorityP265critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.41%
87.5th percentile
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper access control to files within the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to a targeted device. A successful exploit could allow the attacker to gain access to sensitive configuration information, including user authentication credentials.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_rv130w_wireless-n_multifunction_vpn_router_firmware | — | — |
| cisco | rv110w_firmware | <= 1.2.1.7 | — |
| cisco | rv110w_rv130w_and_rv215w_routers | — | — |
| cisco | rv130w_firmware | < 1.0.3.44 | 1.0.3.44 |
| cisco | rv215w_firmware | <= 1.3.0.8 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit involves sending malicious HTTP requests to the web-based management interface of Cisco RV110W, RV130W, or RV215W routers to access files without authentication, due to improper access control ↗
- →The vulnerability is unauthenticated — monitor for unexpected or anomalous requests to the web management interface of these devices from external/untrusted sources, especially requests accessing configuration or credential files ↗
- →Cisco internal bug IDs for this vulnerability are CSCvj23227, CSCvj42744, CSCvj42746 — useful for cross-referencing vendor patch tracking ↗
- ·Affected devices are Cisco RV110W, RV130W, and RV215W routers. The vulnerability exists in the web-based management interface; exposure is highest when the management interface is accessible from untrusted networks. ↗
- ·No workarounds are available; patching via Cisco software updates is the only remediation. ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco RV110W, RV130W, and RV215W Routers Management Interface Information Disclosure Vulnerability
vendor_cisco·2018-09-05·CVSS 7.5
CVE-2018-0425 [HIGH] CWE-200 Cisco RV110W, RV130W, and RV215W Routers Management Interface Information Disclosure Vulnerability
Cisco RV110W, RV130W, and RV215W Routers Management Interface Information Disclosure Vulnerability
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to gain access to sensitive information.
The vulnerability is due to improper access control to files within the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to a targeted device. A successful exploit could allow the attacker to gain access to sensitive configuration information, including user authentication credentials.
Cisco has released software updates that address this vulnerability. There are
Cisco
Cisco RV110W, RV130W, and RV215W Routers Management Interface Information Disclosure Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0425 Cisco RV110W, RV130W, and RV215W Routers Management Interface Information Disclosure Vulnerability
CVE-2018-0425: Cisco RV110W, RV130W, and RV215W Routers Management Interface Information Disclosure Vulnerability
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper access control to files within the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to a targeted device. A successful exploit could allow the attacker to gain access to sensitive configuration information, including user authentication credentials. Cisco has released software updates that address this vulnerabil
GHSA
GHSA-x88p-8c69-vxf4: A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, a
ghsa_unreviewed·2022-05-13
CVE-2018-0425 [CRITICAL] CWE-269 GHSA-x88p-8c69-vxf4: A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, a
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper access control to files within the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to a targeted device. A successful exploit could allow the attacker to gain access to sensitive configuration information, including user authentication credentials.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securitytracker.com/id/1041676https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-rv-routers-disclosurehttp://www.securitytracker.com/id/1041676https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-rv-routers-disclosure
2018-10-05
Published