CVE-2021-1157: Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Stored Cross-Site Scripting Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers?
The vulnerability ID is CVE-2021-1157.
What is the severity of CVE-2021-1157?
The severity of CVE-2021-1157 is medium with a CVSS score of 4.8.
What is the affected software for CVE-2021-1157?
The affected software includes Cisco RV110W, RV130, RV130W, and RV215W Routers with specific firmware versions.
What is the vulnerability description of CVE-2021-1157?
CVE-2021-1157 is a vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers that allows an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.
How can I fix CVE-2021-1157?
To fix CVE-2021-1157, Cisco has provided a software patch or upgrade. Please refer to the Cisco Security Advisory for more information.