VYPR
Unrated severityNVD Advisory· Published Jan 13, 2021· Updated Nov 12, 2024

Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers Management Interface Remote Command Execution and Denial of Service Vulnerabilities

CVE-2021-1171

Description

Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. The vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device. Cisco has not released software updates that address these vulnerabilities.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Multiple Cisco RV series routers have pre-authentication buffer overflow in web management interface, leading to root RCE or DoS.

Vulnerability

Multiple buffer overflow vulnerabilities exist in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W routers running vulnerable firmware. The vulnerabilities are due to improper validation of user-supplied input before being processed by the affected code path in the web interface [1]. An attacker can craft specific HTTP requests to trigger an overflow. The remote management feature (disabled by default) exposes the interface over the WAN, but even without it the interface is accessible via LAN [1]. No fix has been released as of the advisory date.

Exploitation

An attacker must first authenticate with valid administrator credentials to the web management interface [1]. The interface is accessible over LAN by default, or over WAN if remote management is enabled. The attacker then sends specially crafted HTTP requests to an affected device. No user interaction beyond the initial authentication is required [1]. The attacker can reuse the same credentials across multiple CVEs (CVE-2021-1159 through CVE-2021-1171).

Impact

Successful exploitation allows an attacker to execute arbitrary code with root privileges on the underlying operating system, or cause the device to reload (denial of service) [1]. Full compromise of the router is possible, enabling network traffic interception, further lateral movement, or persistent device disruption.

Mitigation

Cisco has not released software updates that address these vulnerabilities. No workarounds are available [1]. Administrators should disable remote management if not needed, restrict LAN access to trusted users, and monitor for future firmware updates. These products may be approaching end of life; upgrade to a supported model is recommended.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.