CVE-2016-1396 describes a cross-site scripting (XSS) vulnerability in the web-based management interface of Cisco RV110W, RV130W, and RV215W devices with specific older firmware versions. This flaw allows remote attackers to inject arbitrary web script or HTML through crafted parameters. The vulnerability is rated Medium severity (CVSS 6.1), indicating it can be exploited remotely with low attack complexity, requiring user interaction, and potentially leading to limited impact on confidentiality and integrity. Despite its age, there is no evidence of active exploitation, nor are there known public exploits in Metasploit or ExploitDB. While there has been some community discussion and media coverage, the vulnerability is not listed on the CISA KEV catalog and is considered inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0.21CPE matchmatch criteria | cpe:2.3:o:cisco:rv130w_wireless-n_multifunction_vpn_router_firmware:1.0.0.21:*:*:*:*:*:*:* | ||
1.0.1.3CPE matchmatch criteria | cpe:2.3:o:cisco:rv130w_wireless-n_multifunction_vpn_router_firmware:1.0.1.3:*:*:*:*:*:*:* | ||
1.0.2.7CPE matchmatch criteria | cpe:2.3:o:cisco:rv130w_wireless-n_multifunction_vpn_router_firmware:1.0.2.7:*:*:*:*:*:*:* | ||
1.1.0.9CPE matchmatch criteria | cpe:2.3:o:cisco:rv110w_wireless-n_vpn_firewall_firmware:1.1.0.9:*:*:*:*:*:*:* | ||
1.2.0.9CPE matchmatch criteria | cpe:2.3:o:cisco:rv110w_wireless-n_vpn_firewall_firmware:1.2.0.9:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.