First published: Wed Jan 11 2023(Updated: )
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow a remote attacker to bypass authentication or execute arbitrary commands on the underlying operating system of an affected device.For more information about these vulnerabilities, see the Details section of this advisory. Cisco has not released software updates to address the vulnerabilities described in this advisory. There are no workarounds that address these vulnerabilities.This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sbr042-multi-vuln-ej76Pke5
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Small Business RV016 Router | ||
Cisco Small Business RV042 Router | ||
Cisco Small Business RV042G | ||
Cisco Small Business RV082 | ||
Cisco Small Business RV320 Router | ||
Cisco Small Business RV325 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of cisco-sa-sbr042-multi-vuln-ej76Pke5 is classified as critical due to the potential for remote exploitation.
To fix cisco-sa-sbr042-multi-vuln-ej76Pke5, update the affected Cisco Small Business routers to the latest firmware version provided by Cisco.
Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 routers are impacted by cisco-sa-sbr042-multi-vuln-ej76Pke5.
Yes, cisco-sa-sbr042-multi-vuln-ej76Pke5 allows an attacker to bypass authentication and gain unauthorized access to the router.
Attacks using cisco-sa-sbr042-multi-vuln-ej76Pke5 can include executing arbitrary commands on the underlying operating system of the router.