Improper input validation in Cisco RV134W Wireless-N VPN Router and Cisco RV132W Wireless-N VPN Router - CVE-2018-0125
Published: February 8, 2018 / Updated: March 25, 2022
Cisco RV134W Wireless-N VPN Router
Cisco RV132W Wireless-N VPN Router
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers due to an incomplete input validation on user-controlled input in an HTTP request. A remote attacker can send a specially crafted HTTP request and cause the device to crash or execute arbitrary code with root privileges.
Successful exploitation of the vulnerability may result in system compromise.