CVE-2020-3331 describes a critical arbitrary code execution vulnerability in the web-based management interface of Cisco RV110W and RV215W Wireless-N VPN Routers. This flaw, stemming from improper input validation, allows an unauthenticated, remote attacker to execute code with root privileges by sending crafted requests. With a CVSS score of 9.8 (Critical) and an EPSS score indicating significant exploitability potential, the vulnerability poses a severe risk. While no public exploit code or active exploitation has been confirmed, it has garnered notable community discussion and media coverage, highlighting its perceived threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.2.8CPE matchmatch criteria | cpe:2.3:o:cisco:rv110w_wireless-n_vpn_firewall_firmware:*:*:*:*:*:*:*:* | ||
< 1.3.1.7CPE matchmatch criteria | cpe:2.3:o:cisco:rv215w_wireless-n_vpn_router_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.