Cisco Small Business Rv Series Router Firmware vulnerabilities
261 known vulnerabilities affecting cisco/cisco_small_business_rv_series_router_firmware.
Total CVEs
261
CISA KEV
8
actively exploited
Public exploits
8
Exploited in wild
15
Severity breakdown
CRITICAL32HIGH188MEDIUM41
Vulnerabilities
Page 1 of 14
CVE-2022-20699P1CRITICALCVSS 9.8KEVPoCvn/a2022-02-10
CVE-2022-20699 [CRITICAL] CWE-121 CVE-2022-20699: Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more informatio
nvd
CVE-2019-1652P1HIGHCVSS 7.2KEVPoCvn/a2019-01-24
CVE-2019-1652 [HIGH] CWE-20 CVE-2019-1652: A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual G
A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands. The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this
nvd
CVE-2023-20118P1HIGHCVSS 7.2KEVv1.0.1.17v1.0.2.03+16 more2023-04-13
CVE-2023-20118 [HIGH] CWE-77 CVE-2023-20118: A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042,
A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device.
This vulnerability is due to improper validation of user input within incoming HTTP packets. An attacker could explo
nvd
CVE-2022-20700P1CRITICALCVSS 9.8KEVvn/a2022-02-10
CVE-2022-20700 [CRITICAL] CWE-121 CVE-2022-20700: Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more informatio
nvd
CVE-2019-15271P1HIGHCVSS 8.8KEV≥ unspecified, < n/a2019-11-26
CVE-2019-15271 [HIGH] CWE-502 CVE-2019-15271: A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Rout
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must have either a valid credential or an active session token. The vulnerability is due to lack of input validation of the HTTP payload.
nvd
CVE-2022-20708P1HIGHCVSS 8.0KEVvn/a2022-02-10
CVE-2022-20708 [HIGH] CWE-121 CVE-2022-20708: Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information ab
nvd
CVE-2022-20703P1HIGHCVSS 8.0KEVvn/a2022-02-10
CVE-2022-20703 [HIGH] CWE-121 CVE-2022-20703: Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information ab
nvd
CVE-2022-20701P1HIGHCVSS 7.8KEVvn/a2022-02-10
CVE-2022-20701 [HIGH] CWE-121 CVE-2022-20701: Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information ab
nvd
CVE-2023-20073P1CRITICALCVSS 9.8ExploitedPoCvn/a2023-04-05
CVE-2023-20073 [CRITICAL] CWE-434 CVE-2023-20073: A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual
A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to insufficient authorization enforcement mechanisms in the context of file uploads. An attacker coul
nvd
CVE-2022-20705P1CRITICALCVSS 9.8ExploitedPoCvn/a2022-02-10
CVE-2022-20705 [CRITICAL] CWE-121 CVE-2022-20705: Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more informatio
nvd
CVE-2021-1472P1CRITICALCVSS 9.8ExploitedPoCvn/a2021-04-08
CVE-2021-1472 [CRITICAL] CWE-119 CVE-2021-1472: Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Seri
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-1473P1CRITICALCVSS 9.8ExploitedPoCvn/a2021-04-08
CVE-2021-1473 [CRITICAL] CWE-119 CVE-2021-1473: Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Seri
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
nvd
CVE-2021-34730P1CRITICALCVSS 9.8ExploitedPoCRansomwarevn/a2021-08-18
CVE-2021-34730 [CRITICAL] CWE-121 CVE-2021-34730: A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130,
A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper valida
nvd
CVE-2022-20707P1HIGHCVSS 7.3ExploitedPoCvn/a2022-02-10
CVE-2022-20707 [HIGH] CWE-121 CVE-2022-20707: Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information ab
nvd
CVE-2020-3451P2MEDIUMCVSS 4.7Exploitedvn/a2020-09-04
CVE-2020-3451 [MEDIUM] CWE-119 CVE-2020-3451: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 Series
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 Series Routers could allow an authenticated, remote attacker with administrative credentials to execute arbitrary commands on the underlying operating system (OS) as a restricted user. For more information about these vulnerabilities, see the Details section of
nvd
CVE-2021-1293P2CRITICALCVSS 9.8vn/a2021-02-04
CVE-2021-1293 [CRITICAL] CWE-472 CVE-2021-1293: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These vulnerabilities exist because HTTP requests are not properly validated. An attacker could e
nvd
CVE-2021-1294P2CRITICALCVSS 9.8vn/a2021-02-04
CVE-2021-1294 [CRITICAL] CWE-472 CVE-2021-1294: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These vulnerabilities exist because HTTP requests are not properly validated. An attacker could e
nvd
CVE-2021-1295P2CRITICALCVSS 9.8vn/a2021-02-04
CVE-2021-1295 [CRITICAL] CWE-472 CVE-2021-1295: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These vulnerabilities exist because HTTP requests are not properly validated. An attacker could e
nvd
CVE-2021-1290P2CRITICALCVSS 9.8vn/a2021-02-04
CVE-2021-1290 [CRITICAL] CWE-472 CVE-2021-1290: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These vulnerabilities exist because HTTP requests are not properly validated. An attacker could e
nvd
CVE-2021-1291P2CRITICALCVSS 9.8vn/a2021-02-04
CVE-2021-1291 [CRITICAL] CWE-472 CVE-2021-1291: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as the root user on an affected device. These vulnerabilities exist because HTTP requests are not properly validated. An attacker could e
nvd
1 / 14Next →