CVE-2020-3332
published 2020-07-16CVE-2020-3332: A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers could allow an authenticated…
PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.18%
86.6th percentile
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers could allow an authenticated, remote attacker to inject arbitrary shell commands that are executed by an affected device. The vulnerability is due to insufficient input validation of user-supplied data. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary shell commands or scripts with root privileges on the affected device.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_rv130w_wireless-n_multifunction_vpn_router_firmware | — | — |
| cisco | rv110w_wireless-n_vpn_firewall_firmware | < 1.2.2.8 | 1.2.2.8 |
| cisco | rv130_vpn_router_firmware | < 1.0.3.55 | 1.0.3.55 |
| cisco | rv130w_wireless-n_multifunction_vpn_router_firmware | < 1.0.3.55 | 1.0.3.55 |
| cisco | rv215w_wireless-n_vpn_router_firmware | < 1.3.1.7 | 1.3.1.7 |
| cisco | small_business_rv110w_rv130_rv130w_and_rv215w_series_routers | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector is a crafted HTTP request to the web-based management interface of affected Cisco Small Business routers (RV110W, RV130, RV130W, RV215W); monitor for anomalous or shell-metacharacter-containing input in web management interface requests ↗
- →Successful exploitation results in arbitrary shell commands or scripts executed with root privileges; monitor for unexpected root-level process spawning from the router's web server process ↗
- →Track Cisco bug IDs CSCvs50846, CSCvs50849, CSCvs50853 for patch status on affected devices; unpatched devices running RV110W, RV130, RV130W, or RV215W firmware should be treated as high-risk ↗
- ·Exploitation requires authentication; however, if management interface credentials are weak or reused, the authentication barrier may be trivially bypassed prior to shell injection ↗
- ·No workarounds are available; the only mitigation is applying the vendor-released software update ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers Command Shell Injection Vulnerability
vendor_cisco·2020-07-15·CVSS 8.1
CVE-2020-3332 [HIGH] CWE-78 Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers Command Shell Injection Vulnerability
Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers Command Shell Injection Vulnerability
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers could allow an authenticated, remote attacker to inject arbitrary shell commands that are executed by an affected device.
The vulnerability is due to insufficient input validation of user-supplied data. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary shell commands or scripts with root privileges on the affected device.
Cisco has released software updates that address this vulnerability. There are no worka
Cisco
Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers Command Shell Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3332 Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers Command Shell Injection Vulnerability
CVE-2020-3332: Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers Command Shell Injection Vulnerability
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers could allow an authenticated, remote attacker to inject arbitrary shell commands that are executed by an affected device. The vulnerability is due to insufficient input validation of user-supplied data. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary shell commands or scripts with root privileges on the affected device. Cisco has released software updates that address this vulnerability. There
GHSA
GHSA-fh59-cj56-8q9p: A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers could allow an authenti
ghsa_unreviewed·2022-05-24
CVE-2020-3332 [HIGH] GHSA-fh59-cj56-8q9p: A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers could allow an authenti
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Series Routers could allow an authenticated, remote attacker to inject arbitrary shell commands that are executed by an affected device. The vulnerability is due to insufficient input validation of user-supplied data. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary shell commands or scripts with root privileges on the affected device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-07-16
Published