imPC@ndo IT

Tracker / CVE-2021-34730

CVE-2021-34730

Critical 9.8

A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of incoming UPnP traffic. An attacker could exploit this vulnerability by sending a crafted UPnP request to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a DoS condition. Cisco has not released software updates that address this vulnerability.

Affected products and versions

cisco application_extension_platform
cisco rv110w_wireless-n_vpn_firewall_firmware
cisco rv130_vpn_router_firmware
cisco rv130w_wireless-n_multifunction_vpn_router_firmware
cisco rv215w_wireless-n_vpn_router_firmware

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References