Executive brief
A vulnerability in the web interface of Cisco RV132W and RV134W VPN routers allows an unauthenticated, remote attacker to execute arbitrary code with root privileges. The issue stems from incomplete input validation of HTTP requests, which can also be exploited to cause a denial of service condition via system reload.
Affected products
- Cisco RV132W ADSL2+ Wireless-N VPN Router Firmware versions prior to 1.0.1.11
- Cisco RV134W VDSL2 Wireless-AC VPN Router Firmware versions prior to 1.0.1.11
Timeline
- 2018-02-07: disclosed: Initial Cisco security advisory published
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-25: exploited: Reported as exploited in the wild per CISA KEV entry