Improper input validation in Cisco RV134W Wireless-N VPN Router and Cisco RV132W Wireless-N VPN Router - CVE-2018-0125
Published: February 8, 2018 / Updated: March 25, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers due to an incomplete input validation on user-controlled input in an HTTP request. A remote attacker can send a specially crafted HTTP request and cause the device to crash or execute arbitrary code with root privileges.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
Cisco RV132W Wireless-N VPN Router