CVE-2018-0424
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
05/10/2018
Last modified:
28/08/2020
Description
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary commands. The vulnerability is due to improper validation of user-supplied input to scripts by the web-based management interface. An attacker could exploit this vulnerability by sending malicious requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary commands with the privileges of the root user.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
9.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:cisco:rv110w_firmware:*:*:*:*:*:*:*:* | 1.2.1.7 (including) | |
| cpe:2.3:h:cisco:rv110w_wireless-n_vpn_firewall:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:rv130w_firmware:*:*:*:*:*:*:*:* | 1.0.3.44 (excluding) | |
| cpe:2.3:h:cisco:rv130w:*:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cisco:rv215w_firmware:*:*:*:*:*:*:*:* | 1.3.0.8 (including) | |
| cpe:2.3:h:cisco:rv215w_wireless-n_vpn_router:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



