CVE-2018-0125 is a critical vulnerability affecting the Cisco RV132W and RV134W VPN Routers, stemming from incomplete input validation in their web interface. An unauthenticated, remote attacker can exploit this by sending a crafted HTTP request, leading to arbitrary code execution with root privileges, full system control, or a denial-of-service condition. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. It is actively exploited in the wild, as indicated by its presence in the KEV catalog and an EPSS score higher than 97% of all CVEs, despite no public exploit code being listed on Metasploit or ExploitDB. The vulnerability has garnered significant community discussion and media coverage, with a fix available in firmware version 1.0.1.11.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:o:cisco:rv132w_firmware:1.0:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:o:cisco:rv134w_firmware:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.