Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Rv042_firmware
(Cisco)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 45 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2020-06-18 | CVE-2020-3295 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary code on an affected device. The vulnerabilities are due to insufficient boundary restrictions on user-supplied input to scripts in the web-based management interface. An attacker with administrative privileges that are... | Rv016_firmware, Rv042_firmware, Rv042g_firmware, Rv082_firmware, Rv320_firmware, Rv325_firmware | 7.2 | ||
2020-06-18 | CVE-2020-3296 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary code on an affected device. The vulnerabilities are due to insufficient boundary restrictions on user-supplied input to scripts in the web-based management interface. An attacker with administrative privileges that are... | Rv016_firmware, Rv042_firmware, Rv042g_firmware, Rv082_firmware, Rv320_firmware, Rv325_firmware | 7.2 | ||
2023-01-20 | CVE-2023-20025 | A vulnerability in the web-based management interface of Cisco Small Business RV042 Series Routers could allow an unauthenticated, remote attacker to bypass authentication on the affected device. This vulnerability is due to incorrect user input validation of incoming HTTP packets. An attacker could exploit this vulnerability by sending crafted requests to the web-based management interface. A successful exploit could allow the attacker to gain root privileges on the affected device. | Rv016_firmware, Rv042_firmware, Rv042g_firmware, Rv082_firmware | 9.8 | ||
2023-01-20 | CVE-2023-20026 | A vulnerability in the web-based management interface of Cisco Small Business Routers RV042 Series could allow an authenticated, remote attacker to inject arbitrary commands on an affected device. This vulnerability is due to improper validation of user input fields within incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an... | Rv016_firmware, Rv042_firmware, Rv042g_firmware, Rv082_firmware | 7.2 | ||
2023-04-05 | CVE-2023-20124 | A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to improper validation of user input within incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface. A successful exploit could allow the attacker to gain... | Rv016_firmware, Rv042_firmware, Rv042g_firmware, Rv082_firmware, Rv320_firmware, Rv325_firmware | 7.2 | ||
2023-04-05 | CVE-2023-20137 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device and then persuading a... | Rv016_firmware, Rv042_firmware, Rv042g_firmware, Rv082_firmware, Rv320_firmware, Rv325_firmware | 6.1 | ||
2023-04-05 | CVE-2023-20138 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device and then persuading a... | Rv016_firmware, Rv042_firmware, Rv042g_firmware, Rv082_firmware, Rv320_firmware, Rv325_firmware | 6.1 | ||
2023-04-05 | CVE-2023-20139 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device and then persuading a... | Rv016_firmware, Rv042_firmware, Rv042g_firmware, Rv082_firmware, Rv320_firmware, Rv325_firmware | 6.1 | ||
2023-04-05 | CVE-2023-20140 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device and then persuading a... | Rv016_firmware, Rv042_firmware, Rv042g_firmware, Rv082_firmware, Rv320_firmware, Rv325_firmware | 6.1 | ||
2023-04-05 | CVE-2023-20141 | Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient input validation by the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device and then persuading a... | Rv016_firmware, Rv042_firmware, Rv042g_firmware, Rv082_firmware, Rv320_firmware, Rv325_firmware | 6.1 |