Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2019-1663Improper Restriction of Operations within the Bounds of a Memory Buffer in Cisco Rv110w Wireless-n VPN Firewall

Severity
9.8CRITICALNVD
EPSS
88.4%
top 0.50%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedFeb 28
Latest updateMay 13

Description

A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied data in the web-based management interface. An attacker could exploit this vulnerability by sending malicious HTTP requests to a targeted device. A su

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages6 packages

CVEListV5cisco/rv130w_wireless-n_multifunction_vpn_routerunspecified1.0.3.45
CVEListV5cisco/rv215w_wireless-n_vpn_routerunspecified1.3.1.1
CVEListV5cisco/rv110w_wireless-n_vpn_firewallunspecified1.2.2.1
NVDcisco/rv110w_firmware< 1.2.2.1
NVDcisco/rv130w_firmware< 1.0.3.45

🔴Vulnerability Details

3
GHSA
GHSA-p7c3-96fj-v9cf: A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, a2022-05-13
CVEList
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability2019-02-28
VulnCheck
Cisco rv110w_firmware Improper Restriction of Operations within the Bounds of a Memory Buffer2019

💥Exploits & PoCs

3
Exploit-DB
Cisco RV110W/RV130(W)/RV215W Routers Management Interface - Remote Command Execution (Metasploit)2019-09-03
Exploit-DB
Cisco RV130W 1.0.3.44 - Remote Stack Overflow2019-06-04
Exploit-DB
Cisco RV130W Routers - Management Interface Remote Command Execution (Metasploit)2019-04-15

📋Vendor Advisories

1
Cisco
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability2019-02-27

🕵️Threat Intelligence

1
Tenable
Management Interfaces in Three Models of Cisco Networking Devices Are Vulnerable to RCE Attacks2019-02-27
CVE-2019-1663 — Cisco vulnerability | cvebase