CVE-2021-1198 describes multiple input validation vulnerabilities in the web-based management interface of several Cisco Small Business RV series routers, including the RV110W, RV130, RV130W, and RV215W. An authenticated, remote attacker could exploit these flaws by sending crafted HTTP requests. Successful exploitation could lead to arbitrary code execution as root or a denial of service (DoS) condition due to unexpected device restarts. The vulnerability has a CVSS score of 7.2 (High), indicating a significant risk. While requiring valid administrator credentials, the attack can be performed remotely over the network with low complexity. The potential impact includes complete system compromise (arbitrary code execution) or service disruption. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The CVE has received minimal community discussion and media coverage, suggesting it is not widely known or actively targeted. Cisco has not released software updates to address these vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.2.8CPE matchmatch criteria | cpe:2.3:o:cisco:rv110w_firmware:1.2.2.8:*:*:*:*:*:*:* | ||
1.3.1.7CPE matchmatch criteria | cpe:2.3:o:cisco:rv110w_firmware:1.3.1.7:*:*:*:*:*:*:* | ||
1.2.2.8CPE matchmatch criteria | cpe:2.3:o:cisco:rv130_vpn_router_firmware:1.2.2.8:*:*:*:*:*:*:* | ||
1.3.1.7CPE matchmatch criteria | cpe:2.3:o:cisco:rv130_vpn_router_firmware:1.3.1.7:*:*:*:*:*:*:* | ||
1.2.2.8CPE matchmatch criteria | cpe:2.3:o:cisco:rv130w_firmware:1.2.2.8:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.