Buffer Overflow in Cisco RV110W, RV130W, and RV215W Router Management Interfaces
CVE-2016-1397

6.5MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
19 June 2016

What is CVE-2016-1397?

A buffer overflow vulnerability exists in the web-based management interface of Cisco RV110W, RV130W, and RV215W routers. This issue arises when remote authenticated users send specially crafted HTTP requests containing specific configuration commands, potentially leading to a denial of service by causing the affected routers to reload. Users of firmware versions prior to 1.2.1.7 for RV110W, 1.0.3.16 for RV130W, and 1.3.0.8 for RV215W are at risk of exploitation. It is recommended that users update to the latest firmware versions to mitigate this risk.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.