First published: Wed Jul 15 2020(Updated: )
A vulnerability in the Telnet service of Cisco Small Business RV110W Wireless-N VPN Firewall Routers could allow an unauthenticated, remote attacker to take full control of the device with a high-privileged account. The vulnerability exists because a system account has a default and static password. An attacker could exploit this vulnerability by using this default account to connect to the affected system. A successful exploit could allow the attacker to gain full control of an affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv110w-static-cred-BMTWBWTy
Credit: Larryxi XDSEC
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco RV110W Wireless-N VPN Firewall Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID cisco-sa-rv110w-static-cred-BMTWBWTy refers to a flaw in the Telnet service of Cisco Small Business RV110W routers that allows unauthorized remote access.
The severity of cisco-sa-rv110w-static-cred-BMTWBWTy is considered high due to the potential for unauthorized remote control of the device.
To fix cisco-sa-rv110w-static-cred-BMTWBWTy, it is recommended to change the default credentials and disable the Telnet service if not needed.
The vulnerability affects users of the Cisco Small Business RV110W Wireless-N VPN Firewall routers.
The potential risks of cisco-sa-rv110w-static-cred-BMTWBWTy include unauthorized access and full control over the affected router by remote attackers.