CVE-2020-3146
published 2020-07-16CVE-2020-3146: Multiple vulnerabilities in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction…
PriorityP262high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.86%
85.1th percentile
Multiple vulnerabilities in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction VPN Router, and RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary code on an affected device. The vulnerabilities are due to improper validation of user-supplied data in the web-based management interface. An attacker could exploit these vulnerabilities by sending malicious HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device as a high-privilege user.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_rv130w_wireless-n_multifunction_vpn_router_firmware | — | — |
| cisco | rv110w_rv130_rv130w_and_rv215w_routers | — | — |
| cisco | rv110w_wireless-n_vpn_firewall_firmware | < 1.2.2.8 | 1.2.2.8 |
| cisco | rv130_firmware | < 1.0.3.55 | 1.0.3.55 |
| cisco | rv130w_firmware | < 1.0.3.55 | 1.0.3.55 |
| cisco | rv215w_firmware | < 1.3.1.7 | 1.3.1.7 |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector is malicious HTTP requests sent to the web-based management interface of affected Cisco RV110W, RV130, RV130W, and RV215W routers; monitor for anomalous or malformed HTTP requests targeting these devices' management interfaces. ↗
- →Successful exploitation results in arbitrary code execution as a high-privilege user on the underlying OS; monitor for unexpected process spawning or privilege escalation on affected router platforms. ↗
- →Root cause is improper validation of user-supplied data in the web-based management interface (CWE-119 buffer overflow/memory corruption); look for oversized or malformed input fields in HTTP POST/GET requests to the management interface. ↗
- →Track Cisco Bug IDs CSCvr94660, CSCvr96222, and CSCvr96225 for patch status and additional technical details related to this CVE cluster. ↗
- ·Exploitation requires prior authentication; unauthenticated attackers cannot directly exploit this vulnerability without valid credentials to the management interface. ↗
- ·No workarounds are available; the only mitigation is applying the vendor-supplied software update. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote Command Execution Multiple Vulnerabilities
vendor_cisco·2020-07-15·CVSS 8.8
CVE-2020-3145 [HIGH] CWE-119 Cisco RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote Command Execution Multiple Vulnerabilities
Cisco RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote Command Execution Multiple Vulnerabilities
Multiple vulnerabilities in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction VPN Router, and RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary code on an affected device.
The vulnerabilities are due to improper validation of user-supplied data in the web-based management interface. An attacker could exploit these vulnerabilities by sending malicious HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device as a high-privilege user.
Cisco ha
Cisco
Cisco RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote Command Execution Multiple Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2020-3146 Cisco RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote Command Execution Multiple Vulnerabilities
CVE-2020-3146: Cisco RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote Command Execution Multiple Vulnerabilities
Multiple vulnerabilities in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction VPN Router, and RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary code on an affected device. The vulnerabilities are due to improper validation of user-supplied data in the web-based management interface. An attacker could exploit these vulnerabilities by sending malicious HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device as a high-privilege u
GHSA
GHSA-rc2g-mp7j-69r8: Multiple vulnerabilities in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multif
ghsa_unreviewed·2022-05-24
CVE-2020-3146 [HIGH] GHSA-rc2g-mp7j-69r8: Multiple vulnerabilities in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multif
Multiple vulnerabilities in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction VPN Router, and RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary code on an affected device. The vulnerabilities are due to improper validation of user-supplied data in the web-based management interface. An attacker could exploit these vulnerabilities by sending malicious HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device as a high-privilege user.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-07-16
Published