cbcvebase.

Cisco Rv130W Firmware vulnerabilities

126 known vulnerabilities affecting cisco/rv130w_firmware.

Total CVEs
126
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH111MEDIUM9

Vulnerabilities

Page 1 of 7
CVE-2019-1663P1CRITICALCVSS 9.8ExploitedPoCfixed in 1.0.3.452019-02-28
CVE-2019-1663 [CRITICAL] CWE-119 CVE-2019-1663: A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, C A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied d
nvd
CVE-2021-1459P2CRITICALCVSS 9.8v1.0.3.552021-04-08
CVE-2021-1459 [CRITICAL] CWE-119 CVE-2021-1459: A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied input in the web-based management interface. An attacker could exploi
nvd
CVE-2020-3144P2CRITICALCVSS 9.8fixed in 1.0.3.552020-07-16
CVE-2020-3144 [CRITICAL] CWE-284 CVE-2020-3144: A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, R A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction VPN Router, and RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary commands with administrative commands on an affected device. T
nvd
CVE-2022-20923P2CRITICALCVSS 9.8v1.0.3.55v1.2.2.8+1 more2022-09-08
CVE-2022-20923 [CRITICAL] CWE-303 CVE-2022-20923: A vulnerability in the IPSec VPN Server authentication functionality of Cisco Small Business RV110W, A vulnerability in the IPSec VPN Server authentication functionality of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to bypass authentication controls and access the IPSec VPN network. This vulnerability is due to the improper implementation of the password validation algorithm. An
nvd
CVE-2018-0425P2CRITICALCVSS 9.8fixed in 1.0.3.442018-10-05
CVE-2018-0425 [CRITICAL] CWE-200 CVE-2018-0425: A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, C A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper access control to files within the we
nvd
CVE-2018-0426P2CRITICALCVSS 9.8fixed in 1.0.3.442018-10-05
CVE-2018-0426 [CRITICAL] CWE-22 CVE-2018-0426: A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, C A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal char
nvd
CVE-2018-0424P2HIGHCVSS 8.8fixed in 1.0.3.442018-10-05
CVE-2018-0424 [HIGH] CWE-77 CVE-2018-0424: A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, C A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary commands. The vulnerability is due to improper validation of user-supplied input to scripts by the we
nvd
CVE-2020-3146P2HIGHCVSS 8.8fixed in 1.0.3.552020-07-16
CVE-2020-3146 [HIGH] CWE-119 CVE-2020-3146: Multiple vulnerabilities in the web-based management interface of the Cisco RV110W Wireless-N VPN Fi Multiple vulnerabilities in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction VPN Router, and RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary code on an affected device. The vulnerabilities are due to improper validation of use
nvd
CVE-2020-3145P2HIGHCVSS 8.8fixed in 1.0.3.552020-07-16
CVE-2020-3145 [HIGH] CWE-119 CVE-2020-3145: Multiple vulnerabilities in the web-based management interface of the Cisco RV110W Wireless-N VPN Fi Multiple vulnerabilities in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction VPN Router, and RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary code on an affected device. The vulnerabilities are due to improper validation of use
nvd
CVE-2026-24700P3HIGHCVSS 7.2v1.0.3.552026-07-08
CVE-2026-24700 [HIGH] CWE-78 CVE-2026-24700: An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisc An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The machine_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root pr
nvd
CVE-2021-1167P3HIGHCVSS 7.2v1.2.2.8v1.3.1.72021-01-13
CVE-2021-1167 [HIGH] CWE-121 CVE-2021-1167: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management
nvd
CVE-2026-24699P3HIGHCVSS 7.2v1.0.3.552026-07-08
CVE-2026-24699 [HIGH] CWE-78 CVE-2026-24699: An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The lan_ipv6_prefixlen configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with ro
nvd
CVE-2026-24698P3HIGHCVSS 7.2v1.0.3.552026-07-08
CVE-2026-24698 [HIGH] CWE-78 CVE-2026-24698: An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" bi An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The model_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands wi
nvd
CVE-2026-24697P3HIGHCVSS 7.2v1.0.3.552026-07-08
CVE-2026-24697 [HIGH] CWE-78 CVE-2026-24697: An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in C An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The wan_hostname configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root
nvd
CVE-2021-1186P3HIGHCVSS 7.2v1.2.2.8v1.3.1.72021-01-13
CVE-2021-1186 [HIGH] CWE-121 CVE-2021-1186: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management
nvd
CVE-2021-1203P3HIGHCVSS 7.2v1.0.3.442021-01-13
CVE-2021-1203 [HIGH] CWE-121 CVE-2021-1203: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management
nvd
CVE-2021-1194P3HIGHCVSS 7.2v1.2.2.8v1.3.1.72021-01-13
CVE-2021-1194 [HIGH] CWE-121 CVE-2021-1194: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management
nvd
CVE-2021-1195P3HIGHCVSS 7.2v1.2.2.8v1.3.1.72021-01-13
CVE-2021-1195 [HIGH] CWE-121 CVE-2021-1195: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management
nvd
CVE-2021-1212P3HIGHCVSS 7.2v1.2.2.8v1.3.1.72021-01-13
CVE-2021-1212 [HIGH] CWE-121 CVE-2021-1212: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management
nvd
CVE-2021-1159P3HIGHCVSS 7.2v1.2.2.8v1.3.1.72021-01-13
CVE-2021-1159 [HIGH] CWE-121 CVE-2021-1159: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management
nvd
Cisco Rv130W Firmware vulnerabilities | cvebase