First published: Wed Apr 07 2021(Updated: )
Multiple vulnerabilities in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code with elevated privileges equivalent to the web service process on an affected device. These vulnerabilities exist because HTTP requests are not properly validated. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to remotely execute arbitrary code on the device. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv34x-rce-8bfG2h6b
Credit: T. Shiomitsu Trend Micro Zero Day Initiative for reporting these vulnerabilities
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco RV340W Firmware | ||
Cisco RV340W Firmware | ||
Cisco RV345P Firmware | ||
Cisco RV345P Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of cisco-sa-sb-rv34x-rce-8bfG2h6b is critical due to the potential for remote code execution by an authenticated attacker.
To fix cisco-sa-sb-rv34x-rce-8bfG2h6b, update your Cisco RV340, RV340W, RV345, or RV345P routers to the latest firmware version released by Cisco.
Organizations using Cisco RV340, RV340W, RV345, and RV345P routers with vulnerable firmware are affected by cisco-sa-sb-rv34x-rce-8bfG2h6b.
cisco-sa-sb-rv34x-rce-8bfG2h6b is a remote code execution vulnerability that allows attackers to execute arbitrary code on affected devices.
No, exploitation of cisco-sa-sb-rv34x-rce-8bfG2h6b requires authentication, allowing only authenticated users to execute arbitrary code.