Cisco RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote Command Execution Multiple Vulnerabilities
Published Jul 16, 2020
8.8
HIGHCVSS 3.1
EPSS 1.84%
Description
Multiple vulnerabilities in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, RV130 VPN Router, RV130W Wireless-N Multifunction VPN Router, and RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary code on an affected device. The vulnerabilities are due to improper validation of user-supplied data in the web-based management interface. An attacker could exploit these vulnerabilities by sending malicious HTTP requests to a targeted device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system of the affected device as a high-privilege user.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Cisco | Cisco RV130W Wireless-N Multifunction VPN Router Firmware | n/a |
|
Configuration 1
- < 1.2.2.8
Configuration 2
- < 1.0.3.55
Configuration 3
- < 1.0.3.55
Configuration 4
- < 1.3.1.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:S/C:P/I:P/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Nov 15, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 1.84% (0.01841) | 78.26th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.84% (0.01841) | 76.15th | v5 (v2026.06.15) |
| Mar 30, 2025 | 1.41% (0.01407) | 78.70th | v4 (v2025.03.14) |
| Mar 29, 2025 | 5.94% (0.05938) | 83.96th | v4 (v2025.03.14) |
| Jul 20, 2024 | 0.18% (0.00180) | 55.64th | v3 (v2023.03.01) |
| May 4, 2024 | 0.18% (0.00180) | 54.90th | v3 (v2023.03.01) |
| Apr 1, 2024 | 0.16% (0.00159) | 51.52th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.17% (0.00165) | 51.34th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.16% (0.01156) | 61.37th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.16% (0.01156) | 58.36th | v2 (v2022.01.01) |
| Feb 4, 2022 | 15.36% (0.15362) | 92.49th | v2 (v2022.01.01) |
| Feb 3, 2022 | 4.23% (0.04230) | 74.42th | v1 |
| Jan 6, 2022 | 4.23% (0.04230) | 74.20th | v1 |
| Jan 5, 2022 | 0.97% (0.00975) | 62.52th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.97% (0.00975) | 0.00th | v1 |
References (1)
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv-rce-m4FEEGWX vendor-advisoryx_refsource_CISCOVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv-rce-m4FEEGWX | vendor-advisoryx_refsource_CISCOVendor Advisory |
Change history (0)
No recorded changes yet.