Cisco Rv215W Firmware vulnerabilities

66 known vulnerabilities affecting cisco/rv215w_firmware.

Total CVEs
66
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH57MEDIUM2

Vulnerabilities

Page 4 of 4
CVE-2019-1663CRITICALCVSS 9.8PoCfixed in 1.3.1.12019-02-28
CVE-2019-1663 [CRITICAL] CWE-119 CVE-2019-1663: A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, C A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper validation of user-supplied d
nvd
CVE-2018-0425CRITICALCVSS 9.8≤ 1.3.0.82018-10-05
CVE-2018-0425 [CRITICAL] CWE-200 CVE-2018-0425: A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, C A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper access control to files within the we
nvd
CVE-2018-0426CRITICALCVSS 9.8≤ 1.3.0.82018-10-05
CVE-2018-0426 [CRITICAL] CWE-22 CVE-2018-0426: A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, C A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal char
nvd
CVE-2018-0424HIGHCVSS 8.8≤ 1.3.0.82018-10-05
CVE-2018-0424 [HIGH] CWE-77 CVE-2018-0424: A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, C A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary commands. The vulnerability is due to improper validation of user-supplied input to scripts by the we
nvd
CVE-2016-1398MEDIUMCVSS 6.5v1.1.0.5v1.1.0.6+3 more2016-07-03
CVE-2016-1398 [MEDIUM] CWE-119 CVE-2016-1398: Buffer overflow in the web-based management interface on Cisco RV110W devices with firmware through Buffer overflow in the web-based management interface on Cisco RV110W devices with firmware through 1.2.1.4, RV130W devices with firmware through 1.0.2.7, and RV215W devices with firmware through 1.3.0.7 allows remote authenticated users to cause a denial of service (device reload) via a crafted HTTP request, aka Bug ID CSCux86669.
nvd
CVE-2014-0683CRITICALCVSS 10.0PoC≤ 1.1.0.52014-03-06
CVE-2014-0683 [CRITICAL] CWE-255 CVE-2014-0683: The web management interface on the Cisco RV110W firewall with firmware 1.2.0.9 and earlier, RV215W The web management interface on the Cisco RV110W firewall with firmware 1.2.0.9 and earlier, RV215W router with firmware 1.1.0.5 and earlier, and CVR100W router with firmware 1.0.1.19 and earlier does not prevent replaying of modified authentication requests, which allows remote attackers to obtain administrative access by leveraging the ability to i
nvd