Path traversal in Cisco Systems, Inc products - CVE-2021-1297
Published: February 4, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error in the web-based management interface. A remote attacker can use the web-based management interface to upload a file to location on an affected device and overwrite files on the target device.
Affected software
Cisco Small Business RV160W Wireless-AC VPN Router
Cisco Small Business RV260 VPN Router
Cisco Small Business RV260P VPN Router with POE
Cisco Small Business RV260W Wireless-AC VPN Router
How to mitigate CVE-2021-1297
Cisco Small Business RV160W Wireless-AC VPN Router - update to 1.0.01.02
Cisco Small Business RV260 VPN Router - update to 1.0.01.02
Cisco Small Business RV260P VPN Router with POE - update to 1.0.01.02
Cisco Small Business RV260W Wireless-AC VPN Router - update to 1.0.01.02