{"cve":"CVE-2021-1472","epss":{"score":0.72028},"mitre":{"cpes":[],"created":"2021-04-08T04:06:54.455000+00:00","description":"Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":5.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"cvssV4_0":{}},"mitre_repo_path":"cves/2021/1xxx/CVE-2021-1472.json","references":["http://packetstormsecurity.com/files/162238/Cisco-RV-Authentication-Bypass-Code-Execution.html","http://seclists.org/fulldisclosure/2021/Apr/39","https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-bypass-inject-Rbhgvfdx"],"title":"Cisco Small Business RV Series Routers Vulnerabilities","updated":"2024-11-08T17:50:36.030000+00:00","vendors":[],"weaknesses":["CWE-119"]},"nvd":{"cpes":["cpe:2.3:h:cisco:rv160:-:*:*:*:*:*:*:*","cpe:2.3:h:cisco:rv160w:-:*:*:*:*:*:*:*","cpe:2.3:h:cisco:rv260:-:*:*:*:*:*:*:*","cpe:2.3:h:cisco:rv260p:-:*:*:*:*:*:*:*","cpe:2.3:h:cisco:rv260w:-:*:*:*:*:*:*:*","cpe:2.3:h:cisco:rv340:-:*:*:*:*:*:*:*","cpe:2.3:h:cisco:rv340w:-:*:*:*:*:*:*:*","cpe:2.3:h:cisco:rv345:-:*:*:*:*:*:*:*","cpe:2.3:h:cisco:rv345p:-:*:*:*:*:*:*:*","cpe:2.3:o:cisco:rv160_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:cisco:rv160w_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:cisco:rv260_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:cisco:rv260p_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:cisco:rv260w_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:cisco:rv340_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:cisco:rv340w_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:cisco:rv345_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:cisco:rv345p_firmware:*:*:*:*:*:*:*:*"],"created":"2021-04-08T04:15:13.687000+00:00","description":"Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.","metrics":{"cvssV2_0":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P"},"cvssV3_0":{},"cvssV3_1":{"score":5.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"cvssV4_0":{}},"nvd_repo_path":"2021/CVE-2021-1472.json","references":["http://packetstormsecurity.com/files/162238/Cisco-RV-Authentication-Bypass-Code-Execution.html","http://seclists.org/fulldisclosure/2021/Apr/39","https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-bypass-inject-Rbhgvfdx"],"title":null,"updated":"2026-06-17T03:31:51.430000+00:00","vendors":["cisco","cisco$PRODUCT$rv160","cisco$PRODUCT$rv160_firmware","cisco$PRODUCT$rv160w","cisco$PRODUCT$rv160w_firmware","cisco$PRODUCT$rv260","cisco$PRODUCT$rv260_firmware","cisco$PRODUCT$rv260p","cisco$PRODUCT$rv260p_firmware","cisco$PRODUCT$rv260w","cisco$PRODUCT$rv260w_firmware","cisco$PRODUCT$rv340","cisco$PRODUCT$rv340_firmware","cisco$PRODUCT$rv340w","cisco$PRODUCT$rv340w_firmware","cisco$PRODUCT$rv345","cisco$PRODUCT$rv345_firmware","cisco$PRODUCT$rv345p","cisco$PRODUCT$rv345p_firmware"],"weaknesses":["CWE-119","CWE-287"]},"opencve":{"changes":[{"created":"2024-11-08T18:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"7256c0b3-e87b-44fc-94db-400aa7061fa4"}],"cpes":{"data":["cpe:2.3:h:cisco:rv160:-:*:*:*:*:*:*:*","cpe:2.3:h:cisco:rv160w:-:*:*:*:*:*:*:*","cpe:2.3:h:cisco:rv260:-:*:*:*:*:*:*:*","cpe:2.3:h:cisco:rv260p:-:*:*:*:*:*:*:*","cpe:2.3:h:cisco:rv260w:-:*:*:*:*:*:*:*","cpe:2.3:h:cisco:rv340:-:*:*:*:*:*:*:*","cpe:2.3:h:cisco:rv340w:-:*:*:*:*:*:*:*","cpe:2.3:h:cisco:rv345:-:*:*:*:*:*:*:*","cpe:2.3:h:cisco:rv345p:-:*:*:*:*:*:*:*","cpe:2.3:o:cisco:rv160_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:cisco:rv160w_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:cisco:rv260_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:cisco:rv260p_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:cisco:rv260w_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:cisco:rv340_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:cisco:rv340w_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:cisco:rv345_firmware:*:*:*:*:*:*:*:*","cpe:2.3:o:cisco:rv345p_firmware:*:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2021-04-08T04:06:54.455000+00:00","provider":"mitre"},"description":{"data":"Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P"},"provider":"nvd"},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":5.3,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.72028},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["http://packetstormsecurity.com/files/162238/Cisco-RV-Authentication-Bypass-Code-Execution.html","http://seclists.org/fulldisclosure/2021/Apr/39","https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-bypass-inject-Rbhgvfdx"],"providers":["mitre","nvd"]},"title":{"data":"Cisco Small Business RV Series Routers Vulnerabilities","provider":"mitre"},"updated":{"data":"2024-11-21T05:44:26.040000+00:00","provider":"nvd"},"vendors":{"data":["cisco","cisco$PRODUCT$rv160","cisco$PRODUCT$rv160_firmware","cisco$PRODUCT$rv160w","cisco$PRODUCT$rv160w_firmware","cisco$PRODUCT$rv260","cisco$PRODUCT$rv260_firmware","cisco$PRODUCT$rv260p","cisco$PRODUCT$rv260p_firmware","cisco$PRODUCT$rv260w","cisco$PRODUCT$rv260w_firmware","cisco$PRODUCT$rv340","cisco$PRODUCT$rv340_firmware","cisco$PRODUCT$rv340w","cisco$PRODUCT$rv340w_firmware","cisco$PRODUCT$rv345","cisco$PRODUCT$rv345_firmware","cisco$PRODUCT$rv345p","cisco$PRODUCT$rv345p_firmware"],"providers":["nvd"]},"weaknesses":{"data":["CWE-119","CWE-287"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2021-04-08T04:06:54.455000+00:00","description":"Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":"Cisco Small Business RV Series Routers Vulnerabilities","updated":"2024-11-08T17:50:31.129000+00:00","vendors":[],"vulnrichment_repo_path":"2021/1xxx/CVE-2021-1472.json","weaknesses":[]}}