Use of hard-coded credentials in Cisco Systems, Inc products - CVE-2020-3330
Published: July 22, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain full access to vulnerable system.
The vulnerability exists due to presence of hard-coded credentials in application code in the Telnet service. A remote unauthenticated attacker can access the affected system using the hard-coded credentials.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
RV130W Wireless-N Multifunction VPN Router
RV215W Wireless-N VPN Router
How to mitigate CVE-2020-3330
RV130W Wireless-N Multifunction VPN Router - update to 1.2.2.8
RV215W Wireless-N VPN Router - update to 1.2.2.8