CVE-2021-1473 describes multiple critical vulnerabilities in the web-based management interface of Cisco Small Business RV Series Routers, including models like the RV340 and RV345. With a CVSS score of 9.8, these flaws allow unauthenticated remote attackers to execute arbitrary commands or bypass authentication to upload files, leading to complete compromise of the affected devices. While not currently listed in CISA's KEV catalog, public exploit modules exist, and its high EPSS score (0.90786) indicates a significant likelihood of exploitation, despite limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.03.21CPE matchmatch criteria | cpe:2.3:o:cisco:rv340_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.03.21CPE matchmatch criteria | cpe:2.3:o:cisco:rv340w_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.03.21CPE matchmatch criteria | cpe:2.3:o:cisco:rv345_firmware:*:*:*:*:*:*:*:* | ||
< 1.0.03.21CPE matchmatch criteria | cpe:2.3:o:cisco:rv345p_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.