cbcvebase.
CVE-2021-1472
published 2021-04-08

CVE-2021-1472: Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOIT
Exploited in the wild
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Affected

11 ranges
VendorProductVersion rangeFixed in
ciscocisco_small_business_rv_series_router_firmware
ciscorv160_firmware< 1.0.01.031.0.01.03
ciscorv160w_firmware< 1.0.01.031.0.01.03
ciscorv260_firmware< 1.0.01.031.0.01.03
ciscorv260p_firmware< 1.0.01.031.0.01.03
ciscorv260w_firmware< 1.0.01.031.0.01.03
ciscorv340_firmware< 1.0.03.211.0.03.21
ciscorv340w_firmware< 1.0.03.211.0.03.21
ciscorv345_firmware< 1.0.03.211.0.03.21
ciscorv345p_firmware< 1.0.03.211.0.03.21
ciscosmall_business_rv_series_routers

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck5.3MEDIUM