cbcvebase.
CVE-2021-34730
published 2021-08-18

CVE-2021-34730: A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated…

PriorityP192critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVRansomwareInitial access
Exploited in the wild
EPSS
13.58%
96.0th percentile
A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of incoming UPnP traffic. An attacker could exploit this vulnerability by sending a crafted UPnP request to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a DoS condition. Cisco has not released software updates that address this vulnerability.

Affected

3 ranges
VendorProductVersion rangeFixed in
ciscoapplication_extension_platform
ciscocisco_small_business_rv_series_router_firmware
ciscosmall_business_rv110w_rv130_rv130w_and_rv215w_routers

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector targets the UPnP service; monitor for crafted/malformed UPnP requests arriving at affected Cisco Small Business routers (RV110W, RV130, RV130W, RV215W)
  • Successful exploitation results in code execution as root or unexpected device reload (DoS); unexplained reloads of these router models should be treated as potential exploitation indicators
  • The vulnerability is unauthenticated and remotely exploitable; no prior credentials or session required — any external UPnP traffic to affected devices should be treated as suspicious
  • Root cause is improper validation of incoming UPnP traffic (CWE-121 stack-based buffer overflow); detection rules should focus on oversized or malformed UPnP SOAP/SSDP payloads directed at the UPnP listener port (typically UDP/1900 and TCP/5000 range) on these devices
  • ·No software fix is available from Cisco; the advisory explicitly states there are no workarounds, meaning vulnerable devices cannot be patched — network-level blocking of UPnP traffic to these devices is the only mitigation

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
vendor_cisco9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.