Cisco Small Business Routers Vulnerable to Arbitrary Code Execution
CVE-2024-20470
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 2 October 2024
Summary
A vulnerability affects the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers, allowing an authenticated remote attacker to execute arbitrary code on the device. The vulnerability arises from inadequate validation of user-supplied input within the management interface. To exploit this vulnerability, an attacker must possess valid administrative credentials and send specially crafted HTTP requests to the vulnerable device. If successful, the exploit could grant the attacker root-level access to the underlying operating system, leading to potential further compromises of the affected network.
Affected Version(s)
Cisco Small Business RV Series Router Firmware 1.0.01.17
Cisco Small Business RV Series Router Firmware 1.0.03.17
Cisco Small Business RV Series Router Firmware 1.0.01.16
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved