Cisco Rv220W Firmware vulnerabilities

4 known vulnerabilities affecting cisco/rv220w_firmware.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2015-6358MEDIUMCVSS 5.9≤ 1.0.4.172017-10-12
CVE-2015-6358 [MEDIUM] CWE-295 CVE-2015-6358: Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the f Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct man-in-the-middle attacks by leveraging knowledge of these certificates and keys from another installation, aka Bug IDs CSCuw46610, CSCuw46620, CSCuw46637,
nvd
CVE-2014-2177CRITICALCVSS 9.0≤ 1.0.5.82014-11-07
CVE-2014-2177 [CRITICAL] CWE-94 CVE-2014-2177: The network-diagnostics administration interface in the Cisco RV router firmware on RV220W devices, The network-diagnostics administration interface in the Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote authenticated users to execute arbitrary commands via a crafted HTTP request, aka Bug ID CSCuh87126.
nvd
CVE-2014-2179MEDIUMCVSS 5.0≤ 1.0.5.82014-11-07
CVE-2014-2179 [MEDIUM] CWE-20 CVE-2014-2179: The Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.1 The Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote attackers to upload files to arbitrary locations via a crafted HTTP request, aka Bug ID CSCuh86998.
nvd
CVE-2014-2178MEDIUMCVSS 6.8≤ 1.0.5.82014-11-07
CVE-2014-2178 [MEDIUM] CWE-352 CVE-2014-2178: Cross-site request forgery (CSRF) vulnerability in the administrative web interface in the Cisco RV Cross-site request forgery (CSRF) vulnerability in the administrative web interface in the Cisco RV router firmware on RV220W devices, before 1.0.5.9 on RV120W devices, and before 1.0.4.14 on RV180 and RV180W devices allows remote attackers to hijack the authentication of administrators, aka Bug ID CSCuh87145.
nvd