CVE-2020-3144: Cisco RV110W, RV130, RV130W, and RV215W Routers Authentication Bypass Vulnerability
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction VPN Router, and RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary commands with administrative commands on an affected device. The vulnerability is due to improper session management on affected devices. An attacker could exploit this vulnerability by sending a crafted HTTP request to the affected device. A successful exploit could allow the attacker to gain administrative access on the affected device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3144?
CVE-2020-3144 is classified as high severity, as it allows unauthenticated remote attackers to bypass authentication.
How do I fix CVE-2020-3144?
To remediate CVE-2020-3144, update your Cisco RV110W, RV130, RV130W, or RV215W router firmware to the latest versions recommended by Cisco.
Which devices are affected by CVE-2020-3144?
CVE-2020-3144 affects Cisco RV110W, RV130, RV130W, and RV215W routers running specific vulnerable firmware versions.
Can CVE-2020-3144 be exploited remotely?
Yes, CVE-2020-3144 can be exploited remotely by attackers without the need for authentication.
What are the implications of CVE-2020-3144?
Exploiting CVE-2020-3144 could allow an attacker to gain unauthorized access and execute arbitrary commands on the affected devices.