CVE-2015-6396 describes a command injection vulnerability in the CLI parser of Cisco RV110W, RV130W, and RV215W devices. This flaw allows a local, authenticated attacker to execute arbitrary shell commands with administrator privileges by providing crafted parameters. Rated with a CVSSv3 score of 7.8 (High), the vulnerability has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog and lacking significant community discussion or media coverage, an exploit for password disclosure and command execution is publicly available on ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:rv110w_wireless-n_vpn_firewall_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:rv130w_wireless-n_multifunction_vpn_router_firmware:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.