A vulnerability in the Universal Plug-and-Play (UPnP) implementation in the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, Layer 2-adjacent attacker to execute arbitrary code or cause a denial of service (DoS) condition. The remote code execution could occur with root privileges. The vulnerability is due to incomplete range checks of the UPnP input data, which could result in a buffer overflow. An attacker could exploit this vulnerability by sending a malicious request to the UPnP listening port of the targeted device. An exploit could allow the attacker to cause the device to reload or potentially execute arbitrary code with root privileges. This vulnerability affects all firmware releases of the Cisco CVR100W Wireless-N VPN Router prior to Firmware Release 1.0.1.22. Cisco Bug IDs: CSCuz72642.
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCisco Rv042
HWCiscoall versionsCisco Rv042g
HWCiscoall versionsCisco Rv082
HWCiscoall versionsCisco Rv110w
HWCiscoall versionsCisco Rv130
HWCiscoall versionsCisco Rv130w
HWCiscoall versionsCisco Rv130 Wf
HWCiscoall versionsCisco Rv130w Wf
HWCiscoall versionsCisco Rv132w
HWCiscoall versionsCisco Rv134w
HWCiscoall versionsCisco Rv215w
HWCiscoall versionsCisco Rv320
HWCiscoall versionsCisco Rv320 Wf
HWCiscoall versionsCisco Rv325
HWCiscoall versionsCisco Rv325 Wf
HWCiscoall versionsCisco Small Business Rv Router Firmware
APPCisco1.0.0.301.0.1.191.0.1.91.0.2.61.0.3.101.0.391.0.4.101.0.4.141.0.5.41.0.5.4\(gd\)1.0.5.51.0.5.61.0.5.81.0.6.6Cisco Small Business Rv Router Firmware 1.0
APPCisco0.2
Related vulnerabilities
RCE i DoS w interfejsie web routerów Cisco RV132W i RV134W VPN
Authentication Bypass z dostępem root w routerach Cisco Small Business RV
RCE w routerach Cisco Small Business RV110W/RV130/RV215W poprzez stack buffer overflow
RCE w interfejsie zarządzania routerów Cisco Small Business RV
Cisco RV110W/RV130/RV215W — pominięcie uwierzytelnienia w interfejsie webowym