cbcvebase.
CVE-2020-3332
published 2020-07-16

CVE-2020-3332: A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers could allow an authenticated…

PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.18%
86.6th percentile
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers could allow an authenticated, remote attacker to inject arbitrary shell commands that are executed by an affected device. The vulnerability is due to insufficient input validation of user-supplied data. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary shell commands or scripts with root privileges on the affected device.

Affected

6 ranges
VendorProductVersion rangeFixed in
ciscocisco_rv130w_wireless-n_multifunction_vpn_router_firmware
ciscorv110w_wireless-n_vpn_firewall_firmware< 1.2.2.81.2.2.8
ciscorv130_vpn_router_firmware< 1.0.3.551.0.3.55
ciscorv130w_wireless-n_multifunction_vpn_router_firmware< 1.0.3.551.0.3.55
ciscorv215w_wireless-n_vpn_router_firmware< 1.3.1.71.3.1.7
ciscosmall_business_rv110w_rv130_rv130w_and_rv215w_series_routers

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is a crafted HTTP request to the web-based management interface of affected Cisco Small Business routers (RV110W, RV130, RV130W, RV215W); monitor for anomalous or shell-metacharacter-containing input in web management interface requests
  • Successful exploitation results in arbitrary shell commands or scripts executed with root privileges; monitor for unexpected root-level process spawning from the router's web server process
  • Track Cisco bug IDs CSCvs50846, CSCvs50849, CSCvs50853 for patch status on affected devices; unpatched devices running RV110W, RV130, RV130W, or RV215W firmware should be treated as high-risk
  • ·Exploitation requires authentication; however, if management interface credentials are weak or reused, the authentication barrier may be trivially bypassed prior to shell injection
  • ·No workarounds are available; the only mitigation is applying the vendor-released software update

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.