CVE-2016-1397 describes a buffer overflow vulnerability in the web-based management interface of several Cisco RV series wireless routers, specifically the RV110W, RV130W, and RV215W models with specific firmware versions. This flaw allows remote authenticated users to trigger a denial of service, causing the device to reload, by sending crafted configuration commands within an HTTP request. Rated with a CVSS score of 6.5 (Medium), the vulnerability has a low attack complexity and requires authentication (PR:L), but can be exploited over the network (AV:N) to achieve high availability impact (A:H). There is no known impact on confidentiality or integrity. Despite a SecurityWeek article mentioning a "critical RCE flaw" in Cisco routers, this specific CVE is not listed in the KEV catalog and has no publicly available Metasploit, Nuclei, or ExploitDB modules. While community discussion and media coverage are present, the vulnerability is currently considered inactive on hot lists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.0.5CPE matchmatch criteria | cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:1.1.0.5:*:*:*:*:*:*:* | ||
1.1.0.6CPE matchmatch criteria | cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:1.1.0.6:*:*:*:*:*:*:* | ||
1.2.0.14CPE matchmatch criteria | cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:1.2.0.14:*:*:*:*:*:*:* | ||
1.2.0.15CPE matchmatch criteria | cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:1.2.0.15:*:*:*:*:*:*:* | ||
1.3.0.7CPE matchmatch criteria | cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:1.3.0.7:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.