← All CVEs

CVE-2021-1472

medium · 5.3

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

5.3
CVSS
71.8%
EPSS (exploit prob.)
99th
EPSS percentile
2021-04-08
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Weaknesses

CWE-119CWE-287

Affected products

VendorProductAffected versions
ciscorv160_firmware< 1.0.01.03
ciscorv160all versions
ciscorv160w_firmware< 1.0.01.03
ciscorv160wall versions
ciscorv260_firmware< 1.0.01.03
ciscorv260all versions
ciscorv260p_firmware< 1.0.01.03
ciscorv260pall versions
ciscorv260w_firmware< 1.0.01.03
ciscorv260wall versions
ciscorv340_firmware< 1.0.03.21
ciscorv340all versions
ciscorv340w_firmware< 1.0.03.21
ciscorv340wall versions
ciscorv345_firmware< 1.0.03.21
ciscorv345all versions
ciscorv345p_firmware< 1.0.03.21
ciscorv345pall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-1472