cve-2021-1472

MEDIUM CVSS 5.3 opencve
Description

Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

Timeline
Published
2021-04-08 04:15 UTC
Last Modified
2026-06-17
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N mitre
3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N nvd
3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N opencve
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cve": "CVE-2021-1472",
  "epss": {
    "score": 0.72028
  },
  "mitre": {
    "cpes": [],
    "created": "2021-04-08T04:06:54.455000+00:00",
    "description": "Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 5.3,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
      },
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2021/1xxx/CVE-2021-1472.json",
    "references": [
      "http://packetstormsecurity.com/files/162238/Cisco-RV-Authentication-Bypass-Code-Execution.html",
      "http://seclists.org/fulldisclosure/2021/Apr/39",
      "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-bypass-inject-Rbhgvfdx"
    ],
    "title": "Cisco Small Business RV Series Routers Vulnerabilities",
    "updated": "2024-11-08T17:50:36.030000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-119"
    ]
  },
  "nvd": {
    "cpes": [
      "cpe:2.3:h:cisco:rv160:-:*:*:*:*:*:*:*",
      "cpe:2.3:h:cisco:rv160w:-:*:*:*:*:*:*:*",
      "cpe:2.3:h:cisco:rv260:-:*:*:*:*:*:*:*",
      "cpe:2.3:h:cisco:rv260p:-:*:*:*:*:*:*:*",
      "cpe:2.3:h:cisco:rv260w:-:*:*:*:*:*:*:*",
      "cpe:2.3:h:cisco:rv340:-:*:*:*:*:*:*:*",
      "cpe:2.3:h:cisco:rv340w:-:*:*:*:*:*:*:*",
      "cpe:2.3:h:cisco:rv345:-:*:*:*:*:*:*:*",
      "cpe:2.3:h:cisco:rv345p:-:*:*:*:*:*:*:*",
      "cpe:2.3:o:cisco:rv160_firmware:*:*:*:*:*:*:*:*",
      "cpe:2.3:o:cisco:rv160w_firmware:*:*:*:*:*:*:*:*",
      "cpe:2.3:o:cisco:rv260_firmware:*:*:*:*:*:*:*:*",
      "cpe:2.3:o:cisco:rv260p_firmware:*:*:*:*:*:*:*:*",
      "cpe:2.3:o:cisco:rv260w_firmware:*:*:*:*:*:*:*:*",
      "cpe:2.3:o:cisco:rv340_firmware:*:*:*:*:*:*:*:*",
      "cpe:2.3:o:cisco:rv340w_firmware:*:*:*:*:*:*:*:*",
      "cpe:2.3:o:cisco:rv345_firmware:*:*:*:*:*:*:*:*",
      "cpe:2.3:o:cisco:rv345p_firmware:*:*:*:*:*:*:*:*"
    ],
    "created": "2021-04-08T04:15:13.687000+00:00",
    "description": "Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.",
    "metrics": {
      "cvssV2_0": {
        "score": 7.5,
        "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
      },
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 5.3,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
      },
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2021/CVE-2021-1472.json",
    "references": [
      "http://packetstormsecurity.com/files/162238/Cisco-RV-Authentication-Bypass-Code-Execution.html",
      "http://seclists.org/fulldisclosure/2021/Apr/39",
      "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-bypass-inject-Rbhgvfdx"
    ],
    "title": null,
    "updated": "2026-06-17T03:31:51.430000+00:00",
    "vendors": [
      "cisco",
      "cisco$PRODUCT$rv160",
      "cisco$PRODUCT$rv160_firmware",
      "cisco$PRODUCT$rv160w",
      "cisco$PRODUCT$rv160w_firmware",
      "cisco$PRODUCT$rv260",
      "cisco$PRODUCT$rv260_firmware",
      "cisco$PRODUCT$rv260p",
      "cisco$PRODUCT$rv260p_firmware",
      "cisco$PRODUCT$rv260w",
      "cisco$PRODUCT$rv260w_firmware",
      "cisco$PRODUCT$rv340",
      "cisco$PRODUCT$rv340_firmware",
      "cisco$PRODUCT$rv340w",
      "cisco$PRODUCT$rv340w_firmware",
      "cisco$PRODUCT$rv345",
      "cisco$PRODUCT$rv345_firmware",
      "cisco$PRODUCT$rv345p",
      "cisco$PRODUCT$rv345p_firmware"
    ],
    "weaknesses": [
      "CWE-119",
      "CWE-287"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2024-11-08T18:15:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "yes",
                    "Exploitation": "poc",
                    "Technical Impact": "partial"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "7256c0b3-e87b-44fc-94db-400aa7061fa4"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:h:cisco:rv160:-:*:*:*:*:*:*:*",
        "cpe:2.3:h:cisco:rv160w:-:*:*:*:*:*:*:*",
        "cpe:2.3:h:cisco:rv260:-:*:*:*:*:*:*:*",
        "cpe:2.3:h:cisco:rv260p:-:*:*:*:*:*:*:*",
        "cpe:2.3:h:cisco:rv260w:-:*:*:*:*:*:*:*",
        "cpe:2.3:h:cisco:rv340:-:*:*:*:*:*:*:*",
        "cpe:2.3:h:cisco:rv340w:-:*:*:*:*:*:*:*",
        "cpe:2.3:h:cisco:rv345:-:*:*:*:*:*:*:*",
        "cpe:2.3:h:cisco:rv345p:-:*:*:*:*:*:*:*",
        "cpe:2.3:o:cisco:rv160_firmware:*:*:*:*:*:*:*:*",
        "cpe:2.3:o:cisco:rv160w_firmware:*:*:*:*:*:*:*:*",
        "cpe:2.3:o:cisco:rv260_firmware:*:*:*:*:*:*:*:*",
        "cpe:2.3:o:cisco:rv260p_firmware:*:*:*:*:*:*:*:*",
        "cpe:2.3:o:cisco:rv260w_firmware:*:*:*:*:*:*:*:*",
        "cpe:2.3:o:cisco:rv340_firmware:*:*:*:*:*:*:*:*",
        "cpe:2.3:o:cisco:rv340w_firmware:*:*:*:*:*:*:*:*",
        "cpe:2.3:o:cisco:rv345_firmware:*:*:*:*:*:*:*:*",
        "cpe:2.3:o:cisco:rv345p_firmware:*:*:*:*:*:*:*:*"
      ],
      "providers": [
        "nvd"
      ]
    },
    "created": {
      "data": "2021-04-08T04:06:54.455000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {
          "score": 7.5,
          "vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
        },
        "provider": "nvd"
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 5.3,
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.72028
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "yes",
            "Exploitation": "poc",
            "Technical Impact": "partial"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "http://packetstormsecurity.com/files/162238/Cisco-RV-Authentication-Bypass-Code-Execution.html",
        "http://seclists.org/fulldisclosure/2021/Apr/39",
        "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-bypass-inject-Rbhgvfdx"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": "Cisco Small Business RV Series Routers Vulnerabilities",
      "provider": "mitre"
    },
    "updated": {
      "data": "2024-11-21T05:44:26.040000+00:00",
      "provider": "nvd"
    },
    "vendors": {
      "data": [
        "cisco",
        "cisco$PRODUCT$rv160",
        "cisco$PRODUCT$rv160_firmware",
        "cisco$PRODUCT$rv160w",
        "cisco$PRODUCT$rv160w_firmware",
        "cisco$PRODUCT$rv260",
        "cisco$PRODUCT$rv260_firmware",
        "cisco$PRODUCT$rv260p",
        "cisco$PRODUCT$rv260p_firmware",
        "cisco$PRODUCT$rv260w",
        "cisco$PRODUCT$rv260w_firmware",
        "cisco$PRODUCT$rv340",
        "cisco$PRODUCT$rv340_firmware",
        "cisco$PRODUCT$rv340w",
        "cisco$PRODUCT$rv340w_firmware",
        "cisco$PRODUCT$rv345",
        "cisco$PRODUCT$rv345_firmware",
        "cisco$PRODUCT$rv345p",
        "cisco$PRODUCT$rv345p_firmware"
      ],
      "providers": [
        "nvd"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-119",
        "CWE-287"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2021-04-08T04:06:54.455000+00:00",
    "description": "Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "yes",
          "Exploitation": "poc",
          "Technical Impact": "partial"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": "Cisco Small Business RV Series Routers Vulnerabilities",
    "updated": "2024-11-08T17:50:31.129000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2021/1xxx/CVE-2021-1472.json",
    "weaknesses": []
  }
}
Enrichment data
View JSON API Download JSON