Information disclosure in Cisco RV134W Wireless-N VPN Router and Cisco RV132W Wireless-N VPN Router - CVE-2018-0127

 

Information disclosure in Cisco RV134W Wireless-N VPN Router and Cisco RV132W Wireless-N VPN Router - CVE-2018-0127

Published: February 7, 2018 / Updated: February 8, 2018


Vulnerability identifier: #VU10422
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-0127
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Cisco Systems, Inc
Affected software:
Cisco RV134W Wireless-N VPN Router
Cisco RV132W Wireless-N VPN Router

Detailed vulnerability description

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The vulnerability exists in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers due to the absence of user authentication requirements for certain pages that are part of the web interface and contain confidential information. A remote attacker can send a specially crafted HTTP request, examine the HTTP response to the request and view configuration parameters, including the administrator password, for the affected device.


How to mitigate CVE-2018-0127

Install update from vendor's website.

Sources