CVE-2016-1395 is a critical remote code execution vulnerability affecting the web-based management interface of Cisco RV110W, RV130W, and RV215W routers running specific older firmware versions. An unauthenticated remote attacker can exploit this flaw by sending a crafted HTTP request, gaining root-level access to the device. With a CVSS score of 9.8, this vulnerability poses a severe risk, allowing for complete compromise of confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is readily available, the vulnerability has garnered some community discussion and media coverage, indicating awareness. Despite its age, the high risk score and potential for unauthenticated root access warrant attention for unpatched systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0.21CPE matchmatch criteria | cpe:2.3:o:cisco:rv130w_wireless-n_multifunction_vpn_router_firmware:1.0.0.21:*:*:*:*:*:*:* | ||
1.0.1.3CPE matchmatch criteria | cpe:2.3:o:cisco:rv130w_wireless-n_multifunction_vpn_router_firmware:1.0.1.3:*:*:*:*:*:*:* | ||
1.0.2.7CPE matchmatch criteria | cpe:2.3:o:cisco:rv130w_wireless-n_multifunction_vpn_router_firmware:1.0.2.7:*:*:*:*:*:*:* | ||
1.1.0.5CPE matchmatch criteria | cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:1.1.0.5:*:*:*:*:*:*:* | ||
1.1.0.6CPE matchmatch criteria | cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:1.1.0.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.