CVE-2021-1473
published 2021-04-08CVE-2021-1473: Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary…
PriorityP191critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
64.16%
99.1th percentile
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_small_business_rv_series_router_firmware | — | — |
| cisco | rv340_firmware | < 1.0.03.21 | 1.0.03.21 |
| cisco | rv340w_firmware | < 1.0.03.21 | 1.0.03.21 |
| cisco | rv345_firmware | < 1.0.03.21 | 1.0.03.21 |
| cisco | rv345p_firmware | < 1.0.03.21 | 1.0.03.21 |
| cisco | small_business_rv_series_routers | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor POST requests to the /upload endpoint on Cisco RV Series routers for suspicious Cookie (sessionid) values containing shell metacharacters (backticks, single quotes, command substitution syntax) indicative of OS command injection. ↗
- →Alert on HTTP requests to /upload with a static or base64-encoded Authorization header (e.g., QUt6NkpTeTE6dmk4cW8=) that bypasses authentication on affected Cisco RV340/RV345 firmware <= 1.0.03.20. ↗
- →Use Shodan/FOFA queries to identify exposed Cisco RV340 management interfaces as potential targets: http.html:"Cisco rv340" or body="cisco rv340". ↗
- →Successful exploitation results in code execution as www-data; monitor for unexpected processes spawned by www-data on Cisco RV340/RV345 devices. ↗
- →Inspect multipart/form-data POST bodies to /upload for the field name 'GXbLINHYkFI' containing 'configurationFILE://Configuration/config.xml' as a fingerprint of exploit activity. ↗
- ·Vulnerability affects RV16X/RV26X firmware versions 1.0.01.02 and before, and RV34X firmware versions 1.0.03.20 and before. Devices on newer firmware are not affected. ↗
- ·The Metasploit module specifically targets RV340, RV340W, RV345, and RV345P models; detection rules should be scoped accordingly. ↗
- ·CVE-2021-1473 (command injection via sessionid cookie) is chained with CVE-2021-1472 (authentication bypass); both CVEs must be considered together for full exploit coverage. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck5.3MEDIUM
vendor_cisco7.3HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Small Business RV Series Routers Vulnerabilities
vendor_cisco·2021-04-07·CVSS 7.3
CVE-2021-1472 [HIGH] CWE-119 Cisco Small Business RV Series Routers Vulnerabilities
Cisco Small Business RV Series Routers Vulnerabilities
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-bypass-inject-Rbhgvfdx
Cisco
Cisco Small Business RV Series Routers Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2021-1473 Cisco Small Business RV Series Routers Vulnerabilities
CVE-2021-1473: Cisco Small Business RV Series Routers Vulnerabilities
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-119, CWE-284, CWE-119, CWE-284
Bug IDs: CSCvw92538, CSCvw92718, CSCvw92723, CSCvw92538, CSCvw92718
GHSA
GHSA-gvf7-w4c7-rvrg: Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers
ghsa_unreviewed·2022-05-24
CVE-2021-1473 [CRITICAL] CWE-119 GHSA-gvf7-w4c7-rvrg: Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
VulnCheck
Cisco RV Series Routers Improper Restriction of Operations within the Bounds of a Memory Buffer
vulncheck·2021·CVSS 5.3
CVE-2021-1473 [MEDIUM] Cisco RV Series Routers Improper Restriction of Operations within the Bounds of a Memory Buffer
Cisco RV Series Routers Improper Restriction of Operations within the Bounds of a Memory Buffer
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
Affected: Cisco RV Series Routers
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://vblocalhost.com/uploads/VB2021-50.pdf; https://media.defense.gov/2024/Sep/18/2003547016/-1/-1/0/CSA-PRC-LINKED-ACTORS-BOTNET.PDF; https://info.greynoise.io/h
No detection rules found.
Nuclei
Cisco Small Business RV Series - OS Command Injection
nuclei·CVSS 9.8
CVE-2021-1472 [CRITICAL] Cisco Small Business RV Series - OS Command Injection
Cisco Small Business RV Series - OS Command Injection
Cisco Small Business RV Series routers RV16X/RV26X versions 1.0.01.02 and before and RV34X versions 1.0.03.20 and before contain multiple OS command injection vulnerabilities in the web-based management interface. A remote attacker can execute arbitrary OS commands via the sessionid cookie or bypass authentication and upload files on an affected device.
Template:
id: CVE-2021-1472
info:
name: Cisco Small Business RV Series - OS Command Injection
author: gy741
severity: critical
description: |
Cisco Small Business RV Series routers RV16X/RV26X versions 1.0.01.02 and before and RV34X versions 1.0.03.20 and before contain multiple OS command injection vulnerabilities in the web-based management interface. A remote attacker can execute
Metasploit
Cisco Small Business RV Series Authentication Bypass and Command Injection
metasploit·CVSS 9.8
CVE-2021-1472 [CRITICAL] Cisco Small Business RV Series Authentication Bypass and Command Injection
Cisco Small Business RV Series Authentication Bypass and Command Injection
This module exploits an authentication bypass (CVE-2021-1472) and command injection (CVE-2021-1473) in the Cisco Small Business RV series of VPN/routers. The device does not adequately verify the credentials in the HTTP Authorization field when requests are made to the /upload endpoint. Then the upload.cgi binary will use the contents of the HTTP Cookie field as part of a `curl` request aimed at an internal endpoint. The curl request is executed using `popen` and allows the attacker to inject commands via the Cookie field. A remote and unauthenticated attacker using this module is able to achieve code execution as `www-data`. This module affects the RV340, RV340w, RV345, and RV345P using firmware versions 1.0.03.20
No writeups or analysis indexed.
http://packetstormsecurity.com/files/162238/Cisco-RV-Authentication-Bypass-Code-Execution.htmlhttp://seclists.org/fulldisclosure/2021/Apr/39https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-bypass-inject-Rbhgvfdxhttp://packetstormsecurity.com/files/162238/Cisco-RV-Authentication-Bypass-Code-Execution.htmlhttp://seclists.org/fulldisclosure/2021/Apr/39https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-bypass-inject-Rbhgvfdx
2021-04-08
Published
Exploited in the wild