First published: Wed Jan 13 2021(Updated: )
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv-stored-xss-LPTQ3EQC
Credit: ADLab Venustech for reporting these vulnerabilities
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Small Business RV110W Wireless-N VPN Firewall | ||
Cisco Small Business RV130 | ||
Cisco Small Business RV130W | ||
Cisco Small Business RV215W |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The cisco-sa-rv-stored-xss-LPTQ3EQC advisory identifies multiple stored cross-site scripting vulnerabilities in the Cisco Small Business RV series routers.
The vulnerability affects users of the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W routers.
An authenticated remote attacker can conduct cross-site scripting (XSS) attacks against users of the affected routers' management interface.
Mitigation involves applying the latest security updates released by Cisco for the affected RV series routers.
Yes, Cisco has released patches that address the stored cross-site scripting vulnerabilities identified in cisco-sa-rv-stored-xss-LPTQ3EQC.